Impact
Keycloak’s SAML Redirect Binding uses custom DEFLATE helpers that do not release native zlib state after use, creating a memory leak. An unauthenticated attacker can send a large number of malformed SAML requests, exhausting the application’s native memory and causing a denial of service. The weakness is a classic memory‑leak flaw (CWE‑401).
Affected Systems
The vulnerability affects Red Hat builds of Keycloak versions 26.4 (including 26.4.16), 26.6 and 26.6.7, as well as Red Hat Data Grid 8, the JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. These products are identified through the associated CPE strings. Administrators should verify whether their installations include any of these affected releases.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity. The EPSS score indicates a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector involves sending repeated malformed SAML redirect requests to an unauthenticated Keycloak service, which could lead to memory exhaustion and service disruption if the leak is not mitigated.
OpenCVE Enrichment