Red Hat SAML protocol implementation of Keycloak: improper input validation
Low3.4CVE-2026-18217 · Published Jul 31, 2026 · updated Aug 7, 2026
A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. When a user authenticates, Keycloak appends its legitimate response to the attacker's parameters. This can cause some service providers to process the attacker's data instead of the real login information, potentially leading to a user being logged into the wrong account.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Build of Keycloak Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet | |
| Red Hat Data Grid 8 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform Expansion Pack Product | all versions | No fix yet |
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-20
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 31 | Red Hat Ansible Automation Platform 2: improper certificate validation | High8.2 | No fix yet |
| Jul 31 | Red Hat gnome-remote-desktop as shipped: resource exhaustion | High7.5 | No fix yet |
| Jul 31 | A flaw was found in 389 Directory Server | High7.5 | No fix yet |
| Jul 31 | Red Hat: buffer overflow | High7.5 | No fix yet |
| Jul 31 | Red Hat Advanced Cluster Security 4: insufficient authenticity check | High8.5 | No fix yet |
| Jul 31 | Red Hat TokenManager: missing authorization | Medium4.2 | No fix yet |