Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

redhat логотип

CVE-2026-1518

7 месяцев назад

A flaw was found in Keycloak’s CIBA feature where insufficient validation of client-configured backchannel notification endpoints could allow blind server-side requests to internal services.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2026-1518

7 месяцев назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. After further review by the Keycloak project and Red Hat, the reported SSRF via client registration/backchannel notification URIs was determined not to constitute a security vulnerability. The reported behavior is expected administrator-controlled functionality, and Keycloak provides documented mitigations through Client Policies, including the Secure Client URIs Pattern executor. Therefore, this CVE has been rejected.

EPSS: Низкий
github логотип

GHSA-fwhw-chw4-gh37

7 месяцев назад

Keycloak Server-Side Request Forgery (SSRF) vulnerability

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-1518

A flaw was found in Keycloak’s CIBA feature where insufficient validation of client-configured backchannel notification endpoints could allow blind server-side requests to internal services.

CVSS3: 2.7
7 месяцев назад
nvd логотип
CVE-2026-1518

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. After further review by the Keycloak project and Red Hat, the reported SSRF via client registration/backchannel notification URIs was determined not to constitute a security vulnerability. The reported behavior is expected administrator-controlled functionality, and Keycloak provides documented mitigations through Client Policies, including the Secure Client URIs Pattern executor. Therefore, this CVE has been rejected.

7 месяцев назад
github логотип
GHSA-fwhw-chw4-gh37

Keycloak Server-Side Request Forgery (SSRF) vulnerability

CVSS3: 2.7
7 месяцев назад

Уязвимостей на страницу