<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:24:43 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-FA60324 — It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-fa60324</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: keycloak&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the keycloak package. It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: keycloak&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the keycloak package. It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-fa60324</guid>
    </item>
    <item>
      <title>cnvd-2017-32893</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-32893</link>
      <description>cnvd-2017-32893</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-32893</guid>
    </item>
    <item>
      <title>EUVD-2026-176414</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-176414</link>
      <description>EUVD-2026-176414</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-176414</guid>
    </item>
    <item>
      <title>fkie_cve-2017-12158</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-12158</link>
      <description>&lt;p&gt;It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-12158</guid>
    </item>
    <item>
      <title>GHSA-v38p-mqq3-m6v5 — Keycloak Reflected XSS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v38p-mqq3-m6v5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-parent&lt;/p&gt;
&lt;p&gt;It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-parent&lt;/p&gt;
&lt;p&gt;It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v38p-mqq3-m6v5</guid>
    </item>
    <item>
      <title>gsd-2017-12158</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-12158</link>
      <description>gsd-2017-12158</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-12158</guid>
    </item>
    <item>
      <title>RHSA-2017:2904 — Red Hat Security Advisory: rh-sso7-keycloak security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:2904</link>
      <description>&lt;p&gt;jasypt: Vulnerable to timing attack against the password hash comparison keycloak: reflected XSS using HOST header keycloak: CSRF token fixation keycloak: resource privilege extension via access token in oauth libpam4j: Account check bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jasypt: Vulnerable to timing attack against the password hash comparison keycloak: reflected XSS using HOST header keycloak: CSRF token fixation keycloak: resource privilege extension via access token in oauth libpam4j: Account check bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:2904</guid>
    </item>
  </channel>
</rss>
