LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-2575

redhat · build of keycloak

Published
CVSS5.3
Severitymedium
WeaknessCWE-409
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Description

A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limits during DEFLATE decompression, leading to an OutOfMemoryError (OOM) and subsequent process termination. This vulnerability allows an attacker to disrupt the availability of the service.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-2575

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-2575.