CVE-2026-7307
EUVD-2026-3088319.05.2026, 12:16
A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | build_of_keycloak | 26.4 ≤ 𝑥 < 26.4.12 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.2 | 26.2.16-1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat build of Keycloak 26.2 | 26.2-21 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat build of Keycloak 26.2 | 26.2-21 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.12-1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-17 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-17 ≤ 𝑥 < * | ADP |
References