<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 22:04:16 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-361702</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-361702</link>
      <description>EUVD-2026-361702</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-361702</guid>
    </item>
    <item>
      <title>fkie_cve-2024-11734</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-11734</link>
      <description>&lt;p&gt;A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-11734</guid>
    </item>
    <item>
      <title>GHSA-w3g8-r9gw-qrh8 — Denial of Service in Keycloak Server via Security Headers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w3g8-r9gw-qrh8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-quarkus-server&lt;/p&gt;
&lt;p&gt;A potential Denial of Service (DoS) vulnerability has been identified in Keycloak, which could allow an administrative user with the rights to change realm settings to disrupt the service. This is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that is already terminated, leading to a failure of said request.&lt;/p&gt;
&lt;p&gt;Service disruption may happen, users will be unable to access applications relying on Keycloak, or any of the consoles provided by Keycloak itself on the affected realm.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-quarkus-server&lt;/p&gt;
&lt;p&gt;A potential Denial of Service (DoS) vulnerability has been identified in Keycloak, which could allow an administrative user with the rights to change realm settings to disrupt the service. This is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that is already terminated, leading to a failure of said request.&lt;/p&gt;
&lt;p&gt;Service disruption may happen, users will be unable to access applications relying on Keycloak, or any of the consoles provided by Keycloak itself on the affected realm.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w3g8-r9gw-qrh8</guid>
    </item>
    <item>
      <title>RHSA-2025:0299 — Red Hat Security Advisory: Red Hat build of Keycloak 26.0.8 Images Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:0299</link>
      <description>&lt;p&gt;org.keycloak:keycloak-quarkus-server: Denial of Service in Keycloak Server via Security Headers org.keycloak:keycloak-quarkus-server: Unrestricted admin use of system and environment variables&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;org.keycloak:keycloak-quarkus-server: Denial of Service in Keycloak Server via Security Headers org.keycloak:keycloak-quarkus-server: Unrestricted admin use of system and environment variables&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:0299</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0056 — Keycloak: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0056</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder um vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder um vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0056</guid>
    </item>
  </channel>
</rss>
