UNKNOWNCVE-2026-4634
Keycloak: keycloak: denial of service via excessive processing of openid connect scope parameters
Platform
java
Component
keycloak
Fixed in
*
A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a Denial of Service (DoS) for the Keycloak server.
How to fix
Actualice Keycloak a una versión parcheada que solucione la vulnerabilidad de denegación de servicio. Consulte los avisos de seguridad de Red Hat (RHSA-2026:6475, RHSA-2026:6476, RHSA-2026:6477) para obtener la versión corregida específica y las instrucciones de actualización.
Monitor your dependencies automatically
Get notified when new vulnerabilities affect your projects. Free forever.
Start free