Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-103884 |
|
Thu, 01 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat build Of Keycloak
Redhat single Sign-on |
|
| Vendors & Products |
Redhat build Of Keycloak
Redhat single Sign-on |
Thu, 01 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash. | |
| Title | Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read | |
| First Time appeared |
Redhat
Redhat build Keycloak Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:/a:redhat:build_keycloak: cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat build Keycloak Redhat red Hat Single Sign On |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-01T18:02:37.056Z
Reserved: 2026-10-01T13:22:41.176Z
Link: CVE-2026-103884
Updated: 2026-10-01T18:02:34.172Z
Status : Awaiting Analysis
Published: 2026-10-01T18:17:12.683
Modified: 2026-10-01T20:36:15.187
Link: CVE-2026-103884
No data.
OpenCVE Enrichment
Updated: 2026-10-01T19:33:25Z