<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:02:50.508493+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-2575</id>
    <title>BIT-keycloak-2026-2575 — Keycloak: keycloak: denial of service due to excessive samlrequest decompression</title>
    <updated>2026-10-03T02:02:50.513936+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: keycloak</p>
<p>A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limits during DEFLATE decompression, leading to an OutOfMemoryError (OOM) and subsequent process termination. This vulnerability allows an attacker to disrupt the availability of the service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-keycloak-2026-2575"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-378004</id>
    <title>EUVD-2026-378004</title>
    <updated>2026-10-03T02:02:50.513984+00:00</updated>
    <content>EUVD-2026-378004</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-378004"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-2575</id>
    <title>fkie_cve-2026-2575</title>
    <updated>2026-10-03T02:02:50.514000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limits during DEFLATE decompression, leading to an OutOfMemoryError (OOM) and subsequent process termination. This vulnerability allows an attacker to disrupt the availability of the service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-2575"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xv6h-r36f-3gp5</id>
    <title>GHSA-xv6h-r36f-3gp5 — Keycloak: Denial of Service due to excessive SAMLRequest decompression</title>
    <updated>2026-10-03T02:02:50.514023+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-saml-adapter-core, Maven: org.keycloak:keycloak-saml-core, Maven: org.keycloak:keycloak-services</p>
<p>A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limits during DEFLATE decompression, leading to an OutOfMemoryError (OOM) and subsequent process termination. This vulnerability allows an attacker to disrupt the availability of the service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xv6h-r36f-3gp5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-026852</id>
    <title>jvndb-2026-026852</title>
    <updated>2026-10-03T02:02:50.514047+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities exist in Hitachi Ops Center Common Services.

CVE-2025-10939, CVE-2025-11537, CVE-2025-11538, CVE-2025-12110, CVE-2025-13467, CVE-2025-13881, CVE-2025-14082, CVE-2025-14083, CVE-2025-14777, CVE-2025-66560, CVE-2026-0707, CVE-2026-0871, CVE-2026-0976, CVE-2026-1035, CVE-2026-1190, CVE-2026-2092, CVE-2026-2575, CVE-2026-2673, CVE-2026-3009, CVE-2026-3121, CVE-2026-3429, CVE-2026-3872, CVE-2026-3911, CVE-2026-4282, CVE-2026-4325, CVE-2026-4634, CVE-2026-22745, CVE-2026-22748, CVE-2026-25854, CVE-2026-40972, CVE-2026-40975</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-026852"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:3947</id>
    <title>RHSA-2026:3947 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.10 Update</title>
    <updated>2026-10-03T02:02:50.514067+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keycloak: Keycloak Authorization Header Parsing Leading to Potential Security Control Bypass org.keycloak/keycloak-services: Keycloak SAML brokering: Response delay due to unchecked NotOnOrAfter in SubjectConfirmationData keycloak-services: Keycloak: Unauthorized access via improper validation of encrypted SAML assertions keycloak: Keycloak: Denial of Service due to excessive SAMLRequest decompression keycloak: Keycloak: Unauthorized authentication via disabled SAML Identity Provider org.keycloak/keycloak-services: Keycloak: Missing Check on Disabled Client for Docker Registry Protocol org.keycloak/keycloak-services: Improper Enforcement of Disabled Identity Provider in IdentityBrokerService (Authentication Bypass) org.keycloak.broker.saml: Keycloak SAML broker: Authentication bypass due to disabled SAML client completing IdP-initiated login</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:3947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0416</id>
    <title>WID-SEC-W-2026-0416 — Keycloak: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T02:02:50.514091+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Keycloak ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0416"/>
  </entry>
</feed>
