These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability in Keycloak allows refresh token replay after server restart when `revokeRefreshToken=true` is enabled with persistent session storage. The flaw stems from internal timing mechanisms resetting on restart, enabling attackers with previously captured refresh tokens to replay them post-revocation. This grants unauthorized account access with potential for information disclosure or privilege e [truncated]
A vulnerability in Keycloak allows a remote attacker with high privileges to trigger a denial of service condition. The flaw exists in the handling of LDAP password policy responses during authentication. An attacker who controls or compromises an upstream LDAP server can send a malformed password policy response that causes an OutOfMemoryError, terminating the Keycloak JVM and denying service to all real [truncated]
A flaw in Keycloak's Client-Initiated Backchannel Authentication (CIBA) flow allows attackers with valid client credentials to bypass brute-force protection on temporarily locked accounts. When an account is locked due to repeated failed login attempts, the CIBA flow continues to permit authentication attempts and token issuance, undermining the intended account lockout security control. This vulnerabilit [truncated]
CVE-2026-9796 is a Time-of-check to time-of-use (TOCTOU) vulnerability in Red Hat Build of Keycloak that allows an authenticated administrator with the `manage-clients` role to escalate their privileges to `realm-admin`. This vulnerability can lead to unauthorized access and lateral movement within the system. The composite role relationship persists even after the attacker's own permissions are revoked a [truncated]
A privilege escalation vulnerability exists in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can assign arbitrary realm roles—including highly privileged roles—to a client's scope mapping. This bypasses intended access controls and causes the injected role to be projected into user authentication tokens when accessing the modified c [truncated]
A vulnerability in Keycloak's SAML ECP (Enhanced Client or Proxy) endpoint allows remote, unauthenticated attackers to enumerate client protocol types through differential error responses. By submitting crafted SOAP requests with varying client IDs and analyzing distinct faultstring values in the XML responses, an attacker can determine whether a given client ID corresponds to a SAML or OpenID Connect (OI [truncated]
A vulnerability in Keycloak allows remote attackers to bypass signature verification in OpenID Connect (OIDC) authorization flows when JSON Web Encryption (JWE) encrypted request objects are used. The flaw occurs when decrypted content is raw JSON rather than a signed JWT, causing Keycloak to incorrectly process unsigned claims without enforcing configured signature policies. This violates OIDC Core and F [truncated]
A flaw in Keycloak's Client Policies allows bypass of the `reject-ropc-grant` executor when certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used. An unauthenticated remote attacker can obtain tokens via Resource Owner Password Credentials (ROPC) grant despite policy configuration intended to block it.
A medium-severity information disclosure vulnerability in Keycloak allows authenticated users with existing organization membership to obtain organization metadata in tokens even after administrators disable the Organizations feature. The flaw affects user-facing APIs including the account API and OIDC token requests with the 'organization' scope. This residual data exposure may lead to incorrect authoriz [truncated]
A privilege escalation vulnerability in Keycloak allows authenticated low-privilege users to gain elevated permissions by exploiting JWT size handling. When an oversized subject_token JWT exceeding 4000 characters is submitted to the TokenEndpoint, the token is silently dropped, causing the system to fall back to client credentials authentication. This fallback mechanism grants the attacker the permission [truncated]
A vulnerability in Samba's vfs_worm module allows authenticated users with write access to bypass write-once, read-many (WORM) protections. The module is designed to prevent file modification after a configurable grace period expires. Due to insufficient validation during rename operations, an attacker can overwrite a WORM-protected file by renaming a newly created file over it. This flaw undermines the c [truncated]
A flaw in Samba's handling of NTFS-style reparse points on read-only shares allows authenticated users with underlying filesystem write permissions to modify reparse point metadata. This could potentially alter SMB-visible file behavior, including converting files into symbolic links or other reparse point types. System administrators and security teams should assess exposure, verify user permissions, and [truncated]
A flaw in Samba's certificate auto-enrollment Group Policy handling allows an attacker to supply a malicious certificate authority certificate by intercepting or redirecting network traffic, potentially enabling interception or spoofing of trusted communications. This issue arises when certificate auto-enrollment is enabled, and Samba retrieves a CA certificate over an unencrypted HTTP connection without [truncated]
A memory corruption vulnerability was found in libgnutls, which could lead to information disclosure. A remote attacker could trigger a short heap overread by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token. This vulnerability affects Red Hat Enterprise Linux 8 systems using libgnutls, and defenders should assess exposure and pr [truncated]
A vulnerability in GnuTLS involves an off-by-one error in the PKCS#12 bag element bounds check. The flaw allows a remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements, leading to memory corruption. This could result in denial of service or potentially other unspecified impacts. The vulnerability is classified as CWE-193 (Off-by-one Err [truncated]
A certificate validation bypass vulnerability exists in GnuTLS where an oversized Subject Alternative Name (SAN) field causes the validation process to incorrectly fall back to checking the Common Name (CN) field. This behavior could allow a remote attacker to present a certificate that passes validation despite not matching the intended hostname, enabling spoofing or man-in-the-middle attacks. The vulner [truncated]
A certificate validation bypass vulnerability exists in GnuTLS where specially crafted certificates containing URI or SRV Subject Alternative Names (SANs) can cause the validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN) field. This fallback behavior may allow attackers to spoof legitimate services or intercept sensitive information by presenting certificates [truncated]
A heap buffer overflow vulnerability in libsolv can lead to out-of-bounds memory access when processing specially crafted `.solv` files. This flaw, found in various Red Hat products, could result in information disclosure, alteration of program execution, or a denial of service. The vulnerability has a CVSS score of 7.8 and is considered HIGH severity.
A command injection vulnerability exists in Samba's printing subsystem. The flaw occurs when Samba passes client-controlled print job description strings to the configured print command via the `%J` substitution character without proper shell escaping. A remote attacker with low privileges can exploit this by submitting a specially crafted print job containing shell metacharacters, potentially achieving r [truncated]
A flaw in KubeVirt's virt-handler component allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.
CVE-2026-9149 describes a heap buffer overflow in libsolv’s repo_add_solv path. A specially crafted .solv file containing negative size values can lead to an undersized allocation followed by an out-of-bounds write, creating a denial-of-service risk. The supplied corpus points to libsolv as the affected project, with Red Hat tracking references and an upstream openSUSE/libsolv pull request suggesting reme [truncated]
CVE-2026-9150 describes a stack-based buffer overflow in libsolv’s Debian metadata parser. According to the supplied record, specially crafted Debian repository metadata containing malicious SHA384 or SHA512 checksum tags can lead to memory corruption and a denial of service. NVD lists the issue with CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, indicating network reachability, no privileges requir [truncated]
CVE-2026-9064 describes a denial-of-service weakness in the 389-ds-base LDAP server where get_ldapmessage_controls_ext() does not cap the number of controls in a single LDAP message. An unauthenticated remote attacker can send a crafted request with very large numbers of minimal controls within the default BER message size limit, driving excessive CPU use and heap allocation. Under concurrent load, the im [truncated]
CVE-2026-7571 describes a high-severity flaw in Keycloak’s OpenID Connect (OIDC) client handling. According to the supplied record, a low-privilege user who knows valid user credentials and a client ID may bypass the control intended to disable the implicit flow by manipulating client data during a session restart. The result can be unauthorized access token issuance, and those tokens may also be exposed [truncated]
CVE-2026-7507 is a high-severity session fixation vulnerability affecting Keycloak login-actions endpoints. According to the supplied description, an unauthenticated attacker can pre-create an authentication session and lure a victim into a crafted link. By abusing the /login-actions/restart endpoint, the attacker can reset authentication flow state without proper CSRF protection or cookie ownership valid [truncated]
CVE-2026-7504 describes an open-redirect validation bypass in Keycloak when clients use a wildcard (*) in Valid Redirect URIs. A crafted redirect URL can slip past validation because Java URI parsing and Keycloak’s check disagree on how to handle the user-info portion of the authority. The result is that a malicious redirect may be allowed after user interaction, which can expose sensitive information wit [truncated]
CVE-2026-7307 describes a network-reachable denial-of-service condition in Keycloak’s SAML handling. A remote, unauthenticated attacker can send specially crafted XML to the SAML endpoint and trigger high CPU usage plus worker thread starvation, making the service unavailable. The supplied record also shows low-confidence vendor attribution, with Red Hat references present in the source metadata.
CVE-2026-4630 is an IDOR weakness in Keycloak’s Authorization Services Protection API. An authenticated client that knows or can obtain another Resource Server’s UUID within the same realm may bypass authorization checks and issue unauthorized GET, PUT, and DELETE requests against protected resources. The result can be information disclosure, unauthorized modification, or deletion of data. The vulnerabili [truncated]
CVE-2026-37982 describes an authentication weakness in Keycloak's WebAuthn flow where an `ExecuteActionsActionToken` can be replayed. If an attacker intercepts the execute-actions email link, they may be able to register their own authenticator to a victim account, creating a path to unauthorized credential enrollment and persistent account takeover. The supplied NVD snapshot lists the issue as CVSS 3.1 6.8 (Medium).
CVE-2026-37981 describes a broken access control flaw in Keycloak’s Account Resources user lookup endpoint. A remote authenticated user who owns at least one User-Managed Access (UMA) resource can send crafted requests with arbitrary usernames or email values and receive full profile objects for unrelated realm users. The result is broad disclosure of personally identifiable information (PII) across the realm.