| CVE |
Severity |
CVSS |
Risk |
Published |
Description |
Impact |
| CVE-2025-7784 |
medium |
6.5 |
6.5 |
10mo ago |
Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled) |
|
| CVE-2024-10270 |
medium |
6.5 |
6.5 |
2y ago |
org.keycloak:keycloak-services has Inefficient Regular Expression Complexity |
|
| CVE-2026-7500 |
medium |
5.4 |
5.4 |
28d ago |
Keycloak has a Forced Browsing issue |
|
| CVE-2025-1391 |
medium |
5.4 |
5.4 |
1y ago |
Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims |
|
| CVE-2025-2559 |
medium |
4.9 |
4.9 |
1y ago |
Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache |
|
| CVE-2026-3911 |
low |
2.7 |
2.7 |
3mo ago |
Keycloak: Information disclosure of disabled user attributes via administrative endpoint |
|