HTTP Redirect Vulnerability in Keycloak Identity Management Solution by Red Hat
CVE-2026-4366

5.8MEDIUM

What is CVE-2026-4366?

A significant flaw exists in Keycloak, an identity and access management solution, related to improper handling of HTTP redirects in specific client configuration requests. This vulnerability may permit attackers to manipulate server behavior into executing unintended requests, granting access to sensitive internal services, including cloud metadata endpoints. Consequently, this exploit could lead to unauthorized information disclosure and enable attackers to gain insights into the internal network topology.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Georgije Vukov (Elite Security Systems) for reporting this issue.
.