Token Management Flaw in Keycloak Server by Red Hat
CVE-2026-1035
What is CVE-2026-1035?
A vulnerability in the Keycloak server arises during the processing of refresh tokens. The issue is located within the TokenManager class, which is responsible for enforcing policies related to refresh token reuse. When strict rotation of refresh tokens is implemented, the lack of atomicity in validating and updating refresh token usage permits simultaneous refresh requests to circumvent the single-use policy. This can lead to unauthorized multiple access token issuance from the same refresh token, compromising the intended security measures associated with token rotation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved