<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:05:34 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-FA60324 — It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-fa60324</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: keycloak&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the keycloak package. It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: keycloak&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the keycloak package. It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-fa60324</guid>
    </item>
    <item>
      <title>cnvd-2017-32892</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-32892</link>
      <description>cnvd-2017-32892</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-32892</guid>
    </item>
    <item>
      <title>EUVD-2026-172895</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-172895</link>
      <description>EUVD-2026-172895</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-172895</guid>
    </item>
    <item>
      <title>fkie_cve-2017-12159</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-12159</link>
      <description>&lt;p&gt;It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-12159</guid>
    </item>
    <item>
      <title>GHSA-7fmw-85qm-h22p — Keycloak CSRF Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7fmw-85qm-h22p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-parent&lt;/p&gt;
&lt;p&gt;It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-parent&lt;/p&gt;
&lt;p&gt;It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7fmw-85qm-h22p</guid>
    </item>
    <item>
      <title>gsd-2017-12159</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-12159</link>
      <description>gsd-2017-12159</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-12159</guid>
    </item>
    <item>
      <title>RHSA-2017:2904 — Red Hat Security Advisory: rh-sso7-keycloak security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:2904</link>
      <description>&lt;p&gt;jasypt: Vulnerable to timing attack against the password hash comparison keycloak: reflected XSS using HOST header keycloak: CSRF token fixation keycloak: resource privilege extension via access token in oauth libpam4j: Account check bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jasypt: Vulnerable to timing attack against the password hash comparison keycloak: reflected XSS using HOST header keycloak: CSRF token fixation keycloak: resource privilege extension via access token in oauth libpam4j: Account check bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:2904</guid>
    </item>
  </channel>
</rss>
