<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:23:54.168838+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-keycloak-2025-12150</id>
    <title>BIT-keycloak-2025-12150 — Org.keycloak/keycloak-services: webauthn attestation statement verification bypass</title>
    <updated>2026-10-04T01:23:54.236811+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: keycloak</p>
<p>A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-keycloak-2025-12150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-349554</id>
    <title>EUVD-2026-349554</title>
    <updated>2026-10-04T01:23:54.236884+00:00</updated>
    <content>EUVD-2026-349554</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-349554"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-12150</id>
    <title>fkie_cve-2025-12150</title>
    <updated>2026-10-04T01:23:54.236901+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-12150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7g5x-9c4v-4w5r</id>
    <title>GHSA-7g5x-9c4v-4w5r — Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass</title>
    <updated>2026-10-04T01:23:54.236928+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-services</p>
<p>A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7g5x-9c4v-4w5r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:21370</id>
    <title>RHSA-2025:21370 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.4 Security Update</title>
    <updated>2026-10-04T01:23:54.236952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>org.keycloak/keycloak-quarkus-server: Unable to restrict access to the admin console keycloak-server: Debug default bind address keycloak: org.keycloak:keycloak-services: User can refresh offline session even after client's offline_access scope was removed org.keycloak/keycloak-services: WebAuthn Attestation Statement Verification Bypass org.keycloak.protocol.oidc.endpoints.LogoutEndpoint: Offline Session takeover due to reused Authentication Session ID</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:21370"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2606</id>
    <title>WID-SEC-W-2025-2606 — Keycloak: Mehrere Schwachstellen</title>
    <updated>2026-10-04T01:23:54.236983+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um beliebigen Programmcode auszuführen, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2606"/>
  </entry>
</feed>
