Denial of Service Vulnerability in Keycloak Open-Source Identity Management Solution
CVE-2026-18212

7.5HIGH

What is CVE-2026-18212?

A vulnerability exists in the SAML Redirect Binding implementation of Keycloak that allows an unauthenticated attacker to exploit memory management flaws. The issue arises from the faulty DEFLATE compression and decompression helpers, which do not properly release native zlib memory. By sending multiple malformed SAML requests, an attacker can lead to native memory exhaustion, resulting in a denial of service for legitimate users. This design oversight poses significant risks to applications relying on Keycloak for identity and access management, necessitating immediate attention to impacted versions.

Affected Version(s)

Red Hat build of Keycloak 26.4 26.4-26

Red Hat build of Keycloak 26.4 26.4-26

Red Hat build of Keycloak 26.4 26.4.16-2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Paul Bottinelli (Trail of Bits in collaboration with OpenAI) for reporting this issue.
.