DO NOT USE THIS CANDIDATE NUMBER. After further review by the Keycloak project and Red Hat, the reported SSRF via client registration/backchannel notification URIs was determined not to constitute a security vulnerability. The reported behavior is expected administrator-controlled functionality, and Keycloak provides documented mitigations through Client Policies, including the Secure Client URIs Pattern executor. Therefore, this CVE has been rejected.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Restrict administrative access to Keycloak, ensuring only trusted personnel can configure client settings, particularly the backchannel_client_notification_endpoint.
- Implement input validation on the backchannel notification endpoint configuration to reject or sanitize untrusted URLs, addressing the underlying CWE‑918 flaw.
- Monitor Keycloak logs for unexpected outbound HTTP traffic and block or quarantine suspicious destinations.
Generated by OpenCVE AI on April 18, 2026 at 00:43 UTC.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fwhw-chw4-gh37 | Keycloak Server-Side Request Forgery (SSRF) vulnerability |
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Keycloak’s CIBA feature where insufficient validation of client-configured backchannel notification endpoints could allow blind server-side requests to internal services. | DO NOT USE THIS CANDIDATE NUMBER. After further review by the Keycloak project and Red Hat, the reported SSRF via client registration/backchannel notification URIs was determined not to constitute a security vulnerability. The reported behavior is expected administrator-controlled functionality, and Keycloak provides documented mitigations through Client Policies, including the Secure Client URIs Pattern executor. Therefore, this CVE has been rejected. |
| Title | Keycloak: blind server-side request forgery (ssrf) via ciba backchannel notification endpoint in keycloak | keycloak: Blind Server-Side Request Forgery (SSRF) via CIBA Backchannel Notification Endpoint in Keycloak |
| CPEs | ||
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| Metrics |
ssvc
|
Mon, 02 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 02 Feb 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Keycloak’s CIBA feature where insufficient validation of client-configured backchannel notification endpoints could allow blind server-side requests to internal services. | |
| Title | Keycloak: blind server-side request forgery (ssrf) via ciba backchannel notification endpoint in keycloak | |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:/a:redhat:build_keycloak: | |
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: REJECTED
Assigner: redhat
Published:
Updated: 2026-07-24T14:07:33.181Z
Reserved: 2026-01-28T08:08:15.419Z
Link: CVE-2026-1518
Updated:
Status : Rejected
Published: 2026-02-02T08:16:06.217
Modified: 2026-07-24T15:17:13.450
Link: CVE-2026-1518
OpenCVE Enrichment
Updated: 2026-04-18T00:45:32Z
-
CWE-918
Server-Side Request Forgery (SSRF)
Github GHSA