PT-2026-66725 · Red Hat · Keycloak

CVE-2026-18209

·

Published

2026-07-31

·

Updated

2026-08-31

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in the keycloak-services component of Keycloak regarding OpenID Connect (OIDC) authentication flows. The security check intended to prevent HTTP parameter pollution—a technique where multiple parameters with the same name are sent to confuse the server—only inspects the query portion of a redirect URL and ignores the fragment portion. If a client is configured with a wildcard redirect URI, an attacker can inject duplicate security parameters into the login response. This may lead to session fixation or account confusion if the client application trusts the injected data over the legitimate security information from Keycloak.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-KEYCLOAK-2026-18209
CVE-2026-18209

Affected Products

Keycloak