PT-2026-26027 · Red Hat · Keycloak

Osidb Bzimport

·

Publicado

2026-03-18

·

Atualizado

2026-06-03

·

CVE-2026-2575

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in Keycloak where an unauthenticated remote attacker can trigger an application-level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server does not enforce size limits during DEFLATE decompression, resulting in an OutOfMemoryError (OOM) and process termination. This allows an attacker to disrupt the availability of the service. The vulnerability involves exploiting the decompression process with a manipulated SAMLRequest sent via the SAML Redirect Binding.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2575
GHSA-XV6H-R36F-3GP5

Produtos afetados

Keycloak