<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:36:46 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-278831</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278831</link>
      <description>EUVD-2026-278831</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278831</guid>
    </item>
    <item>
      <title>fkie_cve-2026-1035</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-1035</link>
      <description>&lt;p&gt;A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not performed atomically. This allows concurrent refresh requests to bypass single-use enforcement and issue multiple access tokens from the same refresh token. As a result, Keycloak’s refresh token rotation hardening can be undermined.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not performed atomically. This allows concurrent refresh requests to bypass single-use enforcement and issue multiple access tokens from the same refresh token. As a result, Keycloak’s refresh token rotation hardening can be undermined.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-1035</guid>
    </item>
    <item>
      <title>GHSA-m2w5-7xhv-w6fh — Keycloak does not validate and update refresh token usage atomically</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m2w5-7xhv-w6fh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-services&lt;/p&gt;
&lt;p&gt;A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not performed atomically. This allows concurrent refresh requests to bypass single-use enforcement and issue multiple access tokens from the same refresh token. As a result, Keycloak’s refresh token rotation hardening can be undermined.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-services&lt;/p&gt;
&lt;p&gt;A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not performed atomically. This allows concurrent refresh requests to bypass single-use enforcement and issue multiple access tokens from the same refresh token. As a result, Keycloak’s refresh token rotation hardening can be undermined.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m2w5-7xhv-w6fh</guid>
    </item>
    <item>
      <title>jvndb-2026-026852</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-026852</link>
      <description>&lt;p&gt;Multiple vulnerabilities exist in Hitachi Ops Center Common Services.&#13;
&#13;
CVE-2025-10939, CVE-2025-11537, CVE-2025-11538, CVE-2025-12110, CVE-2025-13467, CVE-2025-13881, CVE-2025-14082, CVE-2025-14083, CVE-2025-14777, CVE-2025-66560, CVE-2026-0707, CVE-2026-0871, CVE-2026-0976, CVE-2026-1035, CVE-2026-1190, CVE-2026-2092, CVE-2026-2575, CVE-2026-2673, CVE-2026-3009, CVE-2026-3121, CVE-2026-3429, CVE-2026-3872, CVE-2026-3911, CVE-2026-4282, CVE-2026-4325, CVE-2026-4634, CVE-2026-22745, CVE-2026-22748, CVE-2026-25854, CVE-2026-40972, CVE-2026-40975&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities exist in Hitachi Ops Center Common Services.&#13;
&#13;
CVE-2025-10939, CVE-2025-11537, CVE-2025-11538, CVE-2025-12110, CVE-2025-13467, CVE-2025-13881, CVE-2025-14082, CVE-2025-14083, CVE-2025-14777, CVE-2025-66560, CVE-2026-0707, CVE-2026-0871, CVE-2026-0976, CVE-2026-1035, CVE-2026-1190, CVE-2026-2092, CVE-2026-2575, CVE-2026-2673, CVE-2026-3009, CVE-2026-3121, CVE-2026-3429, CVE-2026-3872, CVE-2026-3911, CVE-2026-4282, CVE-2026-4325, CVE-2026-4634, CVE-2026-22745, CVE-2026-22748, CVE-2026-25854, CVE-2026-40972, CVE-2026-40975&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-026852</guid>
    </item>
    <item>
      <title>RHSA-2026:6477 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.11 Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:6477</link>
      <description>&lt;p&gt;keycloak-services: Keycloak Admin REST API: Improper Access Control leads to sensitive role metadata information disclosure keycloak-server: Keycloak: Improper Access Control in Admin REST API leads to information disclosure keycloak: Keycloak IDOR in realm client creating/deleting org.keycloak.protocol.oidc: Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition org.keycloak.protocol.oidc: Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri keycloak: Keycloak: Information disclosure via authorization bypass in Admin API keycloak: org.keycloak/keycloak-services: Keycloak: Privilege escalation via manage-clients permission keycloak: Keycloak: Information Disclosure via improper role enforcement in UMA 2.0 Protection API org.keycloak.services.resources.account: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API keycloak: Keycloak: Information disclosure due to redirect_uri validation bypass org.keycloak.services.resources.admin.UserResource: Keycloak: Information disclosure of disabled user attributes via administrative endpoint keycloak: Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw keycloak: Keycloak: Replay of action tokens via improper handling of single-use entries keycloak: Keycloak: Denial of Service via excessive processing of OpenID Connect scope parameters keycloak: Keycloak: UMA policy bypass allows authen…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;keycloak-services: Keycloak Admin REST API: Improper Access Control leads to sensitive role metadata information disclosure keycloak-server: Keycloak: Improper Access Control in Admin REST API leads to information disclosure keycloak: Keycloak IDOR in realm client creating/deleting org.keycloak.protocol.oidc: Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition org.keycloak.protocol.oidc: Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri keycloak: Keycloak: Information disclosure via authorization bypass in Admin API keycloak: org.keycloak/keycloak-services: Keycloak: Privilege escalation via manage-clients permission keycloak: Keycloak: Information Disclosure via improper role enforcement in UMA 2.0 Protection API org.keycloak.services.resources.account: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API keycloak: Keycloak: Information disclosure due to redirect_uri validation bypass org.keycloak.services.resources.admin.UserResource: Keycloak: Information disclosure of disabled user attributes via administrative endpoint keycloak: Keycloak: Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw keycloak: Keycloak: Replay of action tokens via improper handling of single-use entries keycloak: Keycloak: Denial of Service via excessive processing of OpenID Connect scope parameters keycloak: Keycloak: UMA policy bypass allows authen…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:6477</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-1035</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-1035</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: python-keycloak, Ubuntu:25.10: python-keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not performed atomically. This allows concurrent refresh requests to bypass single-use enforcement and issue multiple access tokens from the same refresh token. As a result, Keycloak’s refresh token rotation hardening can be undermined.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: python-keycloak, Ubuntu:25.10: python-keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not performed atomically. This allows concurrent refresh requests to bypass single-use enforcement and issue multiple access tokens from the same refresh token. As a result, Keycloak’s refresh token rotation hardening can be undermined.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-1035</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0197 — Keycloak: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0197</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0197</guid>
    </item>
  </channel>
</rss>
