<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:12:19.713206+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05659</id>
    <title>bdu:2023-05659</title>
    <updated>2026-10-03T18:12:19.967013+00:00</updated>
    <content>bdu:2023-05659</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05659"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-210678</id>
    <title>EUVD-2026-210678</title>
    <updated>2026-10-03T18:12:19.967068+00:00</updated>
    <content>EUVD-2026-210678</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-210678"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-1664</id>
    <title>fkie_cve-2023-1664</title>
    <updated>2026-10-03T18:12:19.967084+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated by the server. If this happens and the KC_SPI_TRUSTSTORE_FILE_FILE variable is missing/misconfigured, any trustfile may be accepted with the logging information of "Cannot validate client certificate trust: Truststore not available". This may not impact availability as the attacker would have no access to the server, but consumer applications Integrity or Confidentiality may be impacted considering a possible access to them. Considering the environment is correctly set to use "Revalidate Client Certificate" this flaw is avoidable.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-1664"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5cc8-pgp5-7mpm</id>
    <title>GHSA-5cc8-pgp5-7mpm — Keycloak Untrusted Certificate Validation vulnerability</title>
    <updated>2026-10-03T18:12:19.967123+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-core</p>
<p>A flaw was found in keycloak-core. This flaw considers the scenario when using X509 Client Certificate Authenticatior with the option "Revalidate Client Certificate". A user may be able to choose, if directly connect to keycloak (not passing via reverse proxy) a specific certificate. If there's a configuration error in KC_SPI_TRUSTSTORE_FILE_FILE the authenticator allows even with the "Cannot validate client certificate trust: Truststore not available" message as there's no certificate to trust against.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5cc8-pgp5-7mpm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-1664</id>
    <title>gsd-2023-1664</title>
    <updated>2026-10-03T18:12:19.967151+00:00</updated>
    <content>gsd-2023-1664</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-1664"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:3883</id>
    <title>RHSA-2023:3883 — Red Hat Security Advisory: Red Hat Single Sign-On 7.6.4 security update on RHEL 7</title>
    <updated>2026-10-03T18:12:19.967165+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>RHSSO: XSS due to lax URI scheme validation Undertow: Infinite loop in SslConduit during close keycloak: Untrusted Certificate Validation keycloak: oauth client impersonation keycloak: client access via device auth request spoof</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:3883"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0764</id>
    <title>WID-SEC-W-2023-0764 — Keycloak: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T18:12:19.967191+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Keycloak und Red Hat Single Sign On ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0764"/>
  </entry>
</feed>
