Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-103884

Опубликовано: 30 сент. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that it requires non-default configurations (crl-checking-enabled and crldp-checking-enabled) to be active. Successful exploitation allows an attacker to perform arbitrary local file read attempts, potentially leaking file existence or metadata, and cause a Denial of Service through memory exhaustion. The vulnerabilitys root cause is a lack of path normalization and containment checks on the CRL Distribution Point value provided in X.509 certificates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakkeycloak-servicesAffected
Red Hat Build of Keycloakrhbk/keycloak-rhel9Affected
Red Hat Single Sign-On 7keycloak-servicesOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22

EPSS

Процентиль: 11%
0.00213
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
2 дня назад

A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.

CVSS3: 6.5
debian
2 дня назад

A flaw was found in the X.509 client certificate authenticator of Keyc ...

CVSS3: 6.5
github
2 дня назад

A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.

EPSS

Процентиль: 11%
0.00213
Низкий

6.5 Medium

CVSS3