PT-2026-66725 · Red Hat · Keycloak
CVE-2026-18209
·
Published
2026-07-31
·
Updated
2026-08-31
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak (affected versions not specified)
Description
A flaw exists in the keycloak-services component of Keycloak regarding OpenID Connect (OIDC) authentication flows. The security check intended to prevent HTTP parameter pollution—a technique where multiple parameters with the same name are sent to confuse the server—only inspects the query portion of a redirect URL and ignores the fragment portion. If a client is configured with a wildcard redirect URI, an attacker can inject duplicate security parameters into the login response. This may lead to session fixation or account confusion if the client application trusts the injected data over the legitimate security information from Keycloak.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keycloak