Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-3872

Опубликовано: 02 апр. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.

Отчет

This is an Important information disclosure flaw in Keycloak's redirect_uri validation logic. An attacker controlling another path on the same web server could bypass allowed paths in wildcard redirect_uri configurations, potentially leading to access token theft. This affects Red Hat Build of Keycloak (RHBK) versions rhbk-26.2 and rhbk-26.4. Red Hat Build of Keycloak (RHBK) version rhbk-26 is not affected.

Меры по смягчению последствий

To mitigate this vulnerability, avoid using wildcards in redirect_uri configurations within Keycloak. Restricting redirect_uri to explicit, fully qualified URIs prevents the bypass of validation logic. This configuration change may require a service restart or reload to take effect.

Дополнительная информация

Статус:

Important
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2445988keycloak: Keycloak: Information disclosure due to redirect_uri validation bypass

EPSS

Процентиль: 36%
0.0044
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
4 месяца назад

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.

CVSS3: 7.3
debian
4 месяца назад

A flaw was found in Keycloak. This issue allows an attacker, who contr ...

CVSS3: 7.3
github
4 месяца назад

Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint

EPSS

Процентиль: 36%
0.0044
Низкий

7.3 High

CVSS3