Количество 5
Количество 5
CVE-2026-19607
(A flaw was found in the first-broker-login flow of the keycloak-servic ...)
CVE-2026-19607
A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an external provider to trigger a collision in Keycloak, which results in the legitimate user being locked out of their account.
CVE-2026-19607
A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an external provider to trigger a collision in Keycloak, which results in the legitimate user being locked out of their account.
CVE-2026-19607
A flaw was found in the first-broker-login flow of the keycloak-servic ...
GHSA-h87q-rx56-87wm
A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an external provider to trigger a collision in Keycloak, which results in the legitimate user being locked out of their account.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-19607 (A flaw was found in the first-broker-login flow of the keycloak-servic ...) | CVSS3: 5.3 | 1% Низкий | 4 дня назад | |
CVE-2026-19607 A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an external provider to trigger a collision in Keycloak, which results in the legitimate user being locked out of their account. | CVSS3: 5.3 | 1% Низкий | 5 дней назад | |
CVE-2026-19607 A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an external provider to trigger a collision in Keycloak, which results in the legitimate user being locked out of their account. | CVSS3: 5.3 | 1% Низкий | 5 дней назад | |
CVE-2026-19607 A flaw was found in the first-broker-login flow of the keycloak-servic ... | CVSS3: 5.3 | 1% Низкий | 5 дней назад | |
GHSA-h87q-rx56-87wm A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an external provider to trigger a collision in Keycloak, which results in the legitimate user being locked out of their account. | CVSS3: 5.3 | 1% Низкий | 4 дня назад |
Уязвимостей на страницу