Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9689

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 4.2
EPSS Низкий

Описание

A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources.

Отчет

This Moderate severity flaw in Keycloak arises from HTTP parameter pollution when a client is configured with a wildcard redirect URI. An attacker could craft a malicious authorization URL that, if clicked by a user, may lead to the client application incorrectly processing attacker-controlled OIDC response parameters. Exploitation is contingent on the client application employing a 'first-wins' strategy for duplicate query parameters, which is not a universal behavior.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1288
https://bugzilla.redhat.com/show_bug.cgi?id=2481845keycloak: org.keycloak.protocol.oidc: HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604

EPSS

Процентиль: 25%
0.00322
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
nvd
4 месяца назад

A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources.

CVSS3: 4.2
debian
4 месяца назад

A flaw was found in Keycloak, an open-source identity and access manag ...

CVSS3: 4.2
github
4 месяца назад

Keycloak Services has Improper Validation of Consistency within Input

EPSS

Процентиль: 25%
0.00322
Низкий

4.2 Medium

CVSS3