Denial of Service Vulnerability in Keycloak Open-Source Identity Management Solution
CVE-2026-18212
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-18212?
A vulnerability exists in the SAML Redirect Binding implementation of Keycloak that allows an unauthenticated attacker to exploit memory management flaws. The issue arises from the faulty DEFLATE compression and decompression helpers, which do not properly release native zlib memory. By sending multiple malformed SAML requests, an attacker can lead to native memory exhaustion, resulting in a denial of service for legitimate users. This design oversight poses significant risks to applications relying on Keycloak for identity and access management, necessitating immediate attention to impacted versions.
Affected Version(s)
Red Hat build of Keycloak 26.4 26.4-26
Red Hat build of Keycloak 26.4 26.4-26
Red Hat build of Keycloak 26.4 26.4.16-2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved