<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:05:27.214231+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-fa60324</id>
    <title>Withdrawn: CLEANSTART-2026-FA60324 — It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session</title>
    <updated>2026-10-02T20:05:27.325129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: keycloak</p>
<p>Multiple security vulnerabilities affect the keycloak package. It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-fa60324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2017-32892</id>
    <title>cnvd-2017-32892</title>
    <updated>2026-10-02T20:05:27.325192+00:00</updated>
    <content>cnvd-2017-32892</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2017-32892"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-172895</id>
    <title>EUVD-2026-172895</title>
    <updated>2026-10-02T20:05:27.325211+00:00</updated>
    <content>EUVD-2026-172895</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-172895"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-12159</id>
    <title>fkie_cve-2017-12159</title>
    <updated>2026-10-02T20:05:27.325223+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-12159"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7fmw-85qm-h22p</id>
    <title>GHSA-7fmw-85qm-h22p — Keycloak CSRF Vulnerability</title>
    <updated>2026-10-02T20:05:27.325246+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-parent</p>
<p>It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7fmw-85qm-h22p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-12159</id>
    <title>gsd-2017-12159</title>
    <updated>2026-10-02T20:05:27.325265+00:00</updated>
    <content>gsd-2017-12159</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-12159"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2017:2904</id>
    <title>RHSA-2017:2904 — Red Hat Security Advisory: rh-sso7-keycloak security update</title>
    <updated>2026-10-02T20:05:27.325277+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jasypt: Vulnerable to timing attack against the password hash comparison keycloak: reflected XSS using HOST header keycloak: CSRF token fixation keycloak: resource privilege extension via access token in oauth libpam4j: Account check bypass</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2017:2904"/>
  </entry>
</feed>
