<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:04:13.223581+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-16443</id>
    <title>BIT-keycloak-2026-16443 — Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation</title>
    <updated>2026-10-03T11:04:13.318298+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: keycloak</p>
<p>A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-keycloak-2026-16443"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0976</id>
    <title>certfr-2026-avi-0976 — De multiples vulnérabilités ont été découvertes dans KeyCloak. Certaines d'entre elles permettent à un attaquant de pro…</title>
    <updated>2026-10-03T11:04:13.318368+00:00</updated>
    <content>certfr-2026-avi-0976</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0976"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-361821</id>
    <title>EUVD-2026-361821</title>
    <updated>2026-10-03T11:04:13.318396+00:00</updated>
    <content>EUVD-2026-361821</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-361821"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-16443</id>
    <title>fkie_cve-2026-16443</title>
    <updated>2026-10-03T11:04:13.318414+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-16443"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v5j7-jp89-37vr</id>
    <title>GHSA-v5j7-jp89-37vr</title>
    <updated>2026-10-03T11:04:13.318448+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v5j7-jp89-37vr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:50846</id>
    <title>RHSA-2026:50846 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.14 Security Update</title>
    <updated>2026-10-03T11:04:13.318473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keycloak: Keycloak: Privilege escalation through hardcoded role mapper injection keycloak: org.keycloak.protocol.oidc: HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 keycloak: Keycloak: Security policy bypass in JWE-encrypted request object processing keycloak: Keycloak: Brute-force protection bypass in CIBA flow keycloak-policy-enforcer: Keycloak Policy Enforcer: Authorization bypass via incorrect URI comparison keycloak-admin-ui: keycloak-admin-ui:Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions keycloak-services: keycloak-services: FGAP v2 client scope assignment bypass via ClientResource keycloak-services: keycloak: FGAP v2 parent group children endpoint bypasses per-child view permission filter keycloak-services: keycloak-services: DCR protocol mapper type-swap policy bypass allows privilege escalation keycloak-services: keycloak-services: Authorization bypass via unnormalized URI matching in PathMatcher keycloak-services: keycloak-services: LDAP entry-DN user search bypasses configured users DN boundary keycloak-services: keycloak-services: Default DCR policy allows role forgery via User Property mappers io.quarkus/quarkus-rest: io.quarkus/quarkus-vertx-http: io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service keycloak-services: keycloak-services: SAML IdP-initiated broker login bypasses link…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:50846"/>
  </entry>
</feed>
