<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:04:59 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-330488</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330488</link>
      <description>EUVD-2026-330488</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330488</guid>
    </item>
    <item>
      <title>fkie_cve-2026-8830</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-8830</link>
      <description>&lt;p&gt;A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that the newly created credential&amp;#39;s parameters, such as public key algorithms, match the realm&amp;#39;s configured WebAuthn policies. This could lead to the creation of credentials that do not adhere to administrative security requirements, potentially weakening the overall security posture of the system by allowing non-compliant authentication methods.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that the newly created credential&amp;#39;s parameters, such as public key algorithms, match the realm&amp;#39;s configured WebAuthn policies. This could lead to the creation of credentials that do not adhere to administrative security requirements, potentially weakening the overall security posture of the system by allowing non-compliant authentication methods.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-8830</guid>
    </item>
    <item>
      <title>GHSA-g8vr-x4qh-25qg — Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g8vr-x4qh-25qg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-services&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that the newly created credential&amp;#39;s parameters, such as public key algorithms, match the realm&amp;#39;s configured WebAuthn policies. This could lead to the creation of credentials that do not adhere to administrative security requirements, potentially weakening the overall security posture of the system by allowing non-compliant authentication methods.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-services&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that the newly created credential&amp;#39;s parameters, such as public key algorithms, match the realm&amp;#39;s configured WebAuthn policies. This could lead to the creation of credentials that do not adhere to administrative security requirements, potentially weakening the overall security posture of the system by allowing non-compliant authentication methods.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g8vr-x4qh-25qg</guid>
    </item>
    <item>
      <title>RHSA-2026:25097 — Red Hat Security Advisory: Red Hat build of Keycloak 26.6.3 Images Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:25097</link>
      <description>&lt;p&gt;org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: Keycloak: Server-Side Request Forgery via OIDC token endpoint manipulation org.keycloak.keycloak-services: Improper Access Control on Keycloak Server when the account Account API feature is disabled keycloak: org.keycloak/keycloak-services: Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation org.keycloak/keycloak-services: keycloak: org.keycloak.protocol.oidc: Security flaw in org.keycloak/keycloak-services keycloak: Cross-Session Email Verification Proof Not Bound to Upstream Identity in First-Broker-Login keycloak: Keycloak: Information disclosure due to user profile permission bypass keycloak: Keycloak: Privilege escalation due to oversized subject_token JWT keycloak-rhel9: Organization Data Leak After Feature Disabled in Keycloak keycloak: Keycloak: Security restriction bypass allows unauthorized ROPC token acquisition keycloak: Keycloak: Information disclosure via SAML ECP endpoint keycloak: Keycloak: Denial of Service via malformed LDAP password policy response keycloak: Keycloak: Unauthorized account access via replayed refresh tokens after cluster restart keycloak: Keycloak: Denial of Service via malformed Authorization header keycloak: org.keycloak.protocol.oidc.grants.ciba: Keycloak: Information disclosure via CORS header injection due to unvalidated JWT azp claim&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: Keycloak: Server-Side Request Forgery via OIDC token endpoint manipulation org.keycloak.keycloak-services: Improper Access Control on Keycloak Server when the account Account API feature is disabled keycloak: org.keycloak/keycloak-services: Keycloak: Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation org.keycloak/keycloak-services: keycloak: org.keycloak.protocol.oidc: Security flaw in org.keycloak/keycloak-services keycloak: Cross-Session Email Verification Proof Not Bound to Upstream Identity in First-Broker-Login keycloak: Keycloak: Information disclosure due to user profile permission bypass keycloak: Keycloak: Privilege escalation due to oversized subject_token JWT keycloak-rhel9: Organization Data Leak After Feature Disabled in Keycloak keycloak: Keycloak: Security restriction bypass allows unauthorized ROPC token acquisition keycloak: Keycloak: Information disclosure via SAML ECP endpoint keycloak: Keycloak: Denial of Service via malformed LDAP password policy response keycloak: Keycloak: Unauthorized account access via replayed refresh tokens after cluster restart keycloak: Keycloak: Denial of Service via malformed Authorization header keycloak: org.keycloak.protocol.oidc.grants.ciba: Keycloak: Information disclosure via CORS header injection due to unvalidated JWT azp claim&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:25097</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1573 — Keycloak: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1573</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Keycloak ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Keycloak ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1573</guid>
    </item>
  </channel>
</rss>
