X.509 Client-Certificate Authenticator Vulnerability in Keycloak
CVE-2026-105301

4MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
5 October 2026

What is CVE-2026-105301?

A flaw exists in the X.509 client-certificate authenticator of Keycloak, affecting its identity and access management functionalities. When the server is set to validate certificate revocation via CRL Distribution Points or OCSP, an attacker can exploit this vulnerability by presenting a malicious certificate. This certificate can redirect the server to perform unauthorized outbound requests to targeted endpoints before completing the validation process, ultimately leading to a server-side request forgery (SSRF) attack. Ensure proper security measures are in place to mitigate this risk.

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Ahmed (ahmedx90T) for reporting this issue.
.