PT-2026-26027 · Red Hat · Keycloak

·

CVE-2026-2575

·

Publicado

2026-03-18

·

Atualizado

2026-08-25

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in Keycloak where an unauthenticated remote attacker can trigger an application-level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server does not enforce size limits during DEFLATE decompression, resulting in an OutOfMemoryError (OOM) and process termination. This allows an attacker to disrupt the availability of the service. The vulnerability involves exploiting the decompression process with a manipulated SAMLRequest sent via the SAML Redirect Binding.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-KEYCLOAK-2026-2575
CVE-2026-2575
ECHO-12DE-2DCA-D7DC
GHSA-XV6H-R36F-3GP5

Produtos afetados

Keycloak