Description
A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources.
Published: 2026-05-27
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Keycloak allows an attacker to craft a web address that duplicates HTTP response parameters when a client application accepts broad redirect URIs. The duplication can cause the client application to treat attacker‑controlled data as if it were legitimate, potentially bypassing authentication checks or gaining unauthorized access to protected resources. This issue stems from HTTP parameter pollution vulnerabilities, classified under CWE‑1288, and could result in unauthorized privilege escalation within the identity and access management flow.

Affected Systems

The vulnerability affects the Red Hat Build of Keycloak, though no specific version ranges are listed in the advisory. All deployments of this build that permit unrestricted redirect URIs are potentially impacted; clients should review the configuration and update to any fixed releases.

Risk and Exploitability

The CVSS score of 4.2 indicates a medium severity risk. EPSS data are not available, but the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, requiring an attacker to entice a user to click a malicious link that triggers the illicit OIDC response. If successful, the attacker could hijack the authentication response and bypass intended security controls.

Generated by OpenCVE AI on May 27, 2026 at 12:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Keycloak patch or update to a version that addresses the redirect URI duplication issue.
  • Restrict client redirect URIs to a whitelist of exact matches, disallowing wildcard or broad patterns.
  • Implement server‑side validation to canonicalize and deduplicate HTTP response parameters before processing.

Generated by OpenCVE AI on May 27, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Vendors & Products Redhat build Of Keycloak

Wed, 27 May 2026 11:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources.
Title Keycloak: org.keycloak.protocol.oidc: http parameter pollution in oidc redirect uri allows response parameter duplication - #ghi-604
First Time appeared Redhat
Redhat build Keycloak
Weaknesses CWE-1288
CPEs cpe:/a:redhat:build_keycloak:
Vendors & Products Redhat
Redhat build Keycloak
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-05-27T10:44:39.736Z

Reserved: 2026-05-27T10:14:17.955Z

Link: CVE-2026-9689

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-27T12:17:15.513

Modified: 2026-05-27T12:17:15.513

Link: CVE-2026-9689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T12:30:25Z

Weaknesses