Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18208

Опубликовано: 28 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive signed JWT introspection responses, attempts to introspect a token issued for a different audience. Although the endpoint correctly identifies the token as inactive for that client, it still returns the full set of token claims within a signed JWT field. This allows an unauthorized client to bypass audience-based restrictions and access sensitive information contained in the token.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires the attacker to control a confidential client within the same realm and possess a valid token issued for a different audience. Successful exploitation allows an attacker to recover sensitive token claims that should be restricted by audience-based access controls. The vulnerability's root cause is a failure to sanitize the signed JWT field in the introspection response when a token is determined to be inactive due to an audience mismatch.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakkeycloak-servicesFix deferred
Red Hat Build of Keycloakrhbk-keycloak-rhel9/rhbk-keycloak-rhel9Fix deferred
Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9Fix deferred
Red Hat Data Grid 8keycloak-servicesNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesNot affected
Red Hat Single Sign-On 7keycloak-servicesNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2508304keycloak-services: keycloak-services: Inactive out-of-audience token introspection leaks signed JWT claim

EPSS

Процентиль: 10%
0.00201
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
17 дней назад

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive signed JWT introspection responses, attempts to introspect a token issued for a different audience. Although the endpoint correctly identifies the token as inactive for that client, it still returns the full set of token claims within a signed JWT field. This allows an unauthorized client to bypass audience-based restrictions and access sensitive information contained in the token.

CVSS3: 6.5
debian
17 дней назад

A flaw was found in the OIDC token introspection endpoint of the keycl ...

CVSS3: 6.5
github
17 дней назад

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive signed JWT introspection responses, attempts to introspect a token issued for a different audience. Although the endpoint correctly identifies the token as inactive for that client, it still returns the full set of token claims within a signed JWT field. This allows an unauthorized client to bypass audience-based restrictions and access sensitive information contained in the token.

EPSS

Процентиль: 10%
0.00201
Низкий

6.5 Medium

CVSS3