Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319
Red HatCVE-2026-103884

Red Hat Build of Keycloak: information disclosure

Medium6.5CVE-2026-103884 · Published Oct 1, 2026

A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Build of Keycloak
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Single Sign-On 7
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-22

More Red Hat advisories

All Red Hat
Advisory
Red Hat 389-ds-base: resource exhaustion
High7.5Oct 1
Red Hat Satellite 6: SQL injection
Medium6.5Oct 1
Red Hat Satellite 6: observable discrepancy
Medium4.3Oct 1
Red Hat Satellite 6: command injection
Medium5.3Oct 1
Red Hat Satellite 6: command injection
Medium6.7Oct 1
Red Hat Foreman. This vulnerability: information disclosure
Critical9.1Oct 1