PatchSiren cyber security CVE debrief
CVE-2026-105301 Red Hat CVE debrief
A flaw in Keycloak's X.509 client-certificate authenticator can cause unauthorized outbound requests to internal or external endpoints before certificate validation, leading to a blind server-side request forgery (SSRF) attack. This issue arises when the server checks certificate revocation using CRL Distribution Points or OCSP. An attacker can provide a specially crafted certificate pointing to a malicious server, causing Keycloak to make unauthorized requests. Defenders should assess exposure and prioritize verification of Keycloak configurations to prevent unauthorized requests and potential SSRF attacks.
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- CVSS
- MEDIUM 4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-05
Who should care
Defenders responsible for Keycloak deployments, identity and access management systems, and network security should assess exposure and prioritize verification of Keycloak configurations to prevent unauthorized requests and potential SSRF attacks.
Why it matters
CVE-2026-105301 is a medium-severity vulnerability in Keycloak's X.509 client-certificate authenticator that can lead to blind SSRF attacks. Defenders should prioritize verifying Keycloak configurations, checking for unauthorized requests, and implementing compensating controls to mitigate potential SSRF attacks. The vulnerability requires verification of affected versions and remediation steps from the vendor.
- Potential unauthorized outbound requests to internal or external endpoints
- Possible SSRF attacks against Keycloak deployments
- Need for verification of Keycloak configurations and compensating controls
- Potential impact on identity and access management systems
Technical summary
The X.509 client-certificate authenticator in Keycloak is vulnerable to a blind server-side request forgery (SSRF) attack when configured to check certificate revocation using CRL Distribution Points or OCSP. An attacker can provide a specially crafted certificate that points to a malicious server, causing Keycloak to make unauthorized outbound requests to internal or external endpoints before the certificate is fully validated.
Defensive priority
Defenders should prioritize verifying Keycloak configurations, checking for unauthorized requests, and implementing compensating controls to mitigate potential SSRF attacks.
Recommended defensive actions
- Verify Keycloak configurations to prevent unauthorized requests
- Check for signs of SSRF attacks in logs and network traffic
- Implement compensating controls to mitigate potential SSRF attacks
- Monitor for updates from the vendor on affected versions and remediation steps
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Additional verification is needed to determine affected versions and remediation steps. The vulnerability requires verification of affected versions and remediation steps from the vendor. Evidence is limited, and defenders should verify Keycloak configurations and check for unauthorized requests. The source details indicate a medium-severity vulnerability in Keycloak's X.509 client-certificate authenticator.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105301 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105301
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105301 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105301
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-105301
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.