PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105301 Red Hat CVE debrief

A flaw in Keycloak's X.509 client-certificate authenticator can cause unauthorized outbound requests to internal or external endpoints before certificate validation, leading to a blind server-side request forgery (SSRF) attack. This issue arises when the server checks certificate revocation using CRL Distribution Points or OCSP. An attacker can provide a specially crafted certificate pointing to a malicious server, causing Keycloak to make unauthorized requests. Defenders should assess exposure and prioritize verification of Keycloak configurations to prevent unauthorized requests and potential SSRF attacks.

Vendor
Red Hat
Product
Red Hat Build of Keycloak
CVSS
MEDIUM 4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-05
Advisory published
2026-10-05
Advisory updated
2026-10-05

Who should care

Defenders responsible for Keycloak deployments, identity and access management systems, and network security should assess exposure and prioritize verification of Keycloak configurations to prevent unauthorized requests and potential SSRF attacks.

Why it matters

CVE-2026-105301 is a medium-severity vulnerability in Keycloak's X.509 client-certificate authenticator that can lead to blind SSRF attacks. Defenders should prioritize verifying Keycloak configurations, checking for unauthorized requests, and implementing compensating controls to mitigate potential SSRF attacks. The vulnerability requires verification of affected versions and remediation steps from the vendor.

  • Potential unauthorized outbound requests to internal or external endpoints
  • Possible SSRF attacks against Keycloak deployments
  • Need for verification of Keycloak configurations and compensating controls
  • Potential impact on identity and access management systems

Technical summary

The X.509 client-certificate authenticator in Keycloak is vulnerable to a blind server-side request forgery (SSRF) attack when configured to check certificate revocation using CRL Distribution Points or OCSP. An attacker can provide a specially crafted certificate that points to a malicious server, causing Keycloak to make unauthorized outbound requests to internal or external endpoints before the certificate is fully validated.

Defensive priority

Defenders should prioritize verifying Keycloak configurations, checking for unauthorized requests, and implementing compensating controls to mitigate potential SSRF attacks.

Recommended defensive actions

  • Verify Keycloak configurations to prevent unauthorized requests
  • Check for signs of SSRF attacks in logs and network traffic
  • Implement compensating controls to mitigate potential SSRF attacks
  • Monitor for updates from the vendor on affected versions and remediation steps
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Additional verification is needed to determine affected versions and remediation steps. The vulnerability requires verification of affected versions and remediation steps from the vendor. Evidence is limited, and defenders should verify Keycloak configurations and check for unauthorized requests. The source details indicate a medium-severity vulnerability in Keycloak's X.509 client-certificate authenticator.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105301 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105301

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105301 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105301

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.