<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:05:47 +0000</lastBuildDate>
    <item>
      <title>BIT-keycloak-2026-37979 — Keycloak: keycloak: information disclosure via oidc token introspection endpoint audience bypass</title>
      <link>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-37979</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. This access control vulnerability in Keycloak&amp;#39;s OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers, compromising the confidentiality of lightweight access tokens. This issue can be exploited remotely by any confidential client in the realm with valid credentials.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. This access control vulnerability in Keycloak&amp;#39;s OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers, compromising the confidentiality of lightweight access tokens. This issue can be exploited remotely by any confidential client in the realm with valid credentials.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-keycloak-2026-37979</guid>
    </item>
    <item>
      <title>EUVD-2026-319729</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319729</link>
      <description>EUVD-2026-319729</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319729</guid>
    </item>
    <item>
      <title>fkie_cve-2026-37979</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-37979</link>
      <description>&lt;p&gt;A flaw was found in Keycloak. This access control vulnerability in Keycloak&amp;#39;s OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers, compromising the confidentiality of lightweight access tokens. This issue can be exploited remotely by any confidential client in the realm with valid credentials.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak. This access control vulnerability in Keycloak&amp;#39;s OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers, compromising the confidentiality of lightweight access tokens. This issue can be exploited remotely by any confidential client in the realm with valid credentials.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-37979</guid>
    </item>
    <item>
      <title>GHSA-4x37-hw65-52w8 — Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4x37-hw65-52w8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-services&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. This access control vulnerability in Keycloak&amp;#39;s OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers, compromising the confidentiality of lightweight access tokens. This issue can be exploited remotely by any confidential client in the realm with valid credentials.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-services&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. This access control vulnerability in Keycloak&amp;#39;s OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for other resource servers, compromising the confidentiality of lightweight access tokens. This issue can be exploited remotely by any confidential client in the realm with valid credentials.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4x37-hw65-52w8</guid>
    </item>
    <item>
      <title>RHSA-2026:19596 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.12 Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:19596</link>
      <description>&lt;p&gt;keycloak-services: Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling in Keycloak keycloak: Keycloak: Unauthorized resource access and data modification via Insecure Direct Object Reference keycloak: Keycloak: Denial of Service via specially crafted SAML input org.keycloak/keycloak-services: Open redirect when using wildcard valid redirect URIs in Keycloak org.keycloak/keycloak-services: Session fixation in OIDC login flow that can lead to account takeover keycloak: Keycloak: Access token disclosure and implicit flow bypass via forged client data keycloak: org.keycloak.services: Keycloak: Information Disclosure via evaluate-scopes Admin API keycloak: Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass keycloak: org.keycloak.authorization: Keycloak: Information disclosure via broken access control in user lookup endpoint keycloak: org.keycloak.authentication: Keycloak: Unauthorized account takeover via WebAuthn token replay&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;keycloak-services: Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling in Keycloak keycloak: Keycloak: Unauthorized resource access and data modification via Insecure Direct Object Reference keycloak: Keycloak: Denial of Service via specially crafted SAML input org.keycloak/keycloak-services: Open redirect when using wildcard valid redirect URIs in Keycloak org.keycloak/keycloak-services: Session fixation in OIDC login flow that can lead to account takeover keycloak: Keycloak: Access token disclosure and implicit flow bypass via forged client data keycloak: org.keycloak.services: Keycloak: Information Disclosure via evaluate-scopes Admin API keycloak: Keycloak: Information disclosure via OIDC token introspection endpoint audience bypass keycloak: org.keycloak.authorization: Keycloak: Information disclosure via broken access control in user lookup endpoint keycloak: org.keycloak.authentication: Keycloak: Unauthorized account takeover via WebAuthn token replay&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:19596</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1612 — Keycloak: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1612</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen, Daten zu manipulieren, Sicherheitsvorkehrungen zu umgehen und einen Denial of Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Informationen offenzulegen, Daten zu manipulieren, Sicherheitsvorkehrungen zu umgehen und einen Denial of Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1612</guid>
    </item>
  </channel>
</rss>
