Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9689

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 4.2

Описание

A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources.

Отчет

This Moderate severity flaw in Keycloak arises from HTTP parameter pollution when a client is configured with a wildcard redirect URI. An attacker could craft a malicious authorization URL that, if clicked by a user, may lead to the client application incorrectly processing attacker-controlled OIDC response parameters. Exploitation is contingent on the client application employing a 'first-wins' strategy for duplicate query parameters, which is not a universal behavior.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakrhbk/keycloak-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1288
https://bugzilla.redhat.com/show_bug.cgi?id=2481845keycloak: org.keycloak.protocol.oidc: HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
nvd
2 месяца назад

A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources.

CVSS3: 4.2
debian
2 месяца назад

A flaw was found in Keycloak, an open-source identity and access manag ...

CVSS3: 4.2
github
2 месяца назад

Keycloak Services has Improper Validation of Consistency within Input

4.2 Medium

CVSS3