<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T00:25:51.876299+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-361702</id>
    <title>EUVD-2026-361702</title>
    <updated>2026-10-06T00:25:51.948388+00:00</updated>
    <content>EUVD-2026-361702</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-361702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-11734</id>
    <title>fkie_cve-2024-11734</title>
    <updated>2026-10-06T00:25:51.948424+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-11734"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w3g8-r9gw-qrh8</id>
    <title>GHSA-w3g8-r9gw-qrh8 — Denial of Service in Keycloak Server via Security Headers</title>
    <updated>2026-10-06T00:25:51.948459+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-quarkus-server</p>
<p>A potential Denial of Service (DoS) vulnerability has been identified in Keycloak, which could allow an administrative user with the rights to change realm settings to disrupt the service. This is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that is already terminated, leading to a failure of said request.</p>
<p>Service disruption may happen, users will be unable to access applications relying on Keycloak, or any of the consoles provided by Keycloak itself on the affected realm.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w3g8-r9gw-qrh8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:0299</id>
    <title>RHSA-2025:0299 — Red Hat Security Advisory: Red Hat build of Keycloak 26.0.8 Images Update</title>
    <updated>2026-10-06T00:25:51.948487+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>org.keycloak:keycloak-quarkus-server: Denial of Service in Keycloak Server via Security Headers org.keycloak:keycloak-quarkus-server: Unrestricted admin use of system and environment variables</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:0299"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0056</id>
    <title>WID-SEC-W-2025-0056 — Keycloak: Mehrere Schwachstellen</title>
    <updated>2026-10-06T00:25:51.948509+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder um vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0056"/>
  </entry>
</feed>
