Vulnerability Database

With exploit

org.keycloak / keycloak-services

Title Severity Exploit Date Affected Version
CVE-2025-3910 Medium Apr 30, 2025 < 26.2.2
CVE-2025-3501 High Apr 30, 2025 < 26.2.2
CVE-2025-2559 Medium Mar 25, 2025 <= 26.1.4
CVE-2025-1391 Medium Mar 10, 2025 >= 26.1.0 < 26.1.3
< 26.0.10
CVE-2023-0657 Low Nov 17, 2024 < 22.0.10
>= 23.0.0 < 24.0.3
CVE-2022-2232 High Nov 14, 2024 < 23.0.1
CVE-2024-3656 High Oct 9, 2024 < 24.0.5
Keycloak Denial of Service via account lockout Low Jun 12, 2024 < 24.0.0
Keycloak's improper input validation allows using email as username Low Jun 12, 2024 < 24.0.1
Keycloak exposes sensitive information in Pushed Authorization Requests (PAR) High Jun 10, 2024 < 24.0.5