Description
A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.
Published: 2026-10-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Local File Disclosure
Action: Apply Patch
AI Analysis

Impact

An attacker can supply a crafted client certificate that causes the Keycloak X.509 authenticator to read arbitrary files from the server filesystem or load extremely large files, leading to disclosure of sensitive data or a memory exhaustion induced crash. The flaw lies in the CRL Distribution Point path validation, which is not properly sanitized. The weakness is a local path traversal error that can be exploited when CRL checking is enabled.

Affected Systems

The vulnerability affects Red Hat Build of Keycloak and Red Hat Single Sign-On 7. No specific affected versions are listed, so any installation that includes the X.509 client certificate authenticator with CRL checking enabled is potentially impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score is not available, so the current exploitation probability has not been quantified. The vulnerability is not listed in CISA KEV, suggesting there are no known active exploits at this time. The likely attack vector requires the attacker to be able to influence the client certificate presented to the server, which typically means they have some foothold in the authentication process or can inject certificates into the system.

Generated by OpenCVE AI on October 1, 2026 at 18:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Red Hat Build of Keycloak to the latest release that contains the fix for this CRL distribution point path validation issue.
  • If an update cannot be applied immediately, disable CRL Distribution Point checking in the Keycloak configuration to eliminate the faulty path traversal processing.
  • Limit the file system permissions of the Keycloak service so that it cannot read sensitive directories, reducing the impact even if a path traversal attempt succeeds.

Generated by OpenCVE AI on October 1, 2026 at 18:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.
Title Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-22
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Subscriptions

Redhat Build Keycloak Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-01T18:02:37.056Z

Reserved: 2026-10-01T13:22:41.176Z

Link: CVE-2026-103884

cve-icon Vulnrichment

Updated: 2026-10-01T18:02:34.172Z

cve-icon NVD

Status : Received

Published: 2026-10-01T18:17:12.683

Modified: 2026-10-01T19:17:18.523

Link: CVE-2026-103884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:00:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')