CVE-2026-4634
A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a Denial of Service (DoS) for the Keycloak server.
Vendor
-
Product
-
CWE
Yayın Tarihi
2026-04-02 13:16:27
Güncelleme
2026-04-03 16:10:52
Source Identifier
secalert@redhat.com
KEV Date Added
-