Red Hat Build of Keycloak: improper signature check
Low3.7CVE-2026-18569 · Published Aug 4, 2026 · updated Aug 10, 2026
A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Build of Keycloak Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet | |
| Red Hat Data Grid 8 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform Expansion Pack Product | all versions | No fix yet |
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-347
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 4 | Red Hat SSSD: out-of-bounds read | Medium5.5 | No fix yet |
| Aug 4 | Red Hat Enterprise Linux 10: server-side request forgery | Medium5.4 | 5.80 |
| Aug 4 | Red Hat Enterprise Linux 10: out-of-bounds read | Medium6.5 | 5.80 |
| Aug 4 | Red Hat popt: code execution | Low2.5 | No fix yet |
| Aug 4 | Red Hat SSSD: uninitialized resource | Low3.3 | No fix yet |
| Aug 4 | Red Hat Enterprise Linux: heap buffer overflow | High7.3 | No fix yet |