UNKNOWNCVE-2026-4634

Keycloak: keycloak: denial of service via excessive processing of openid connect scope parameters

Platform

java

Component

keycloak

Fixed in

*

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a Denial of Service (DoS) for the Keycloak server.

How to fix

Actualice Keycloak a una versión parcheada que solucione la vulnerabilidad de denegación de servicio. Consulte los avisos de seguridad de Red Hat (RHSA-2026:6475, RHSA-2026:6476, RHSA-2026:6477) para obtener la versión corregida específica y las instrucciones de actualización.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free