Known vulnerabilities in DuoUniversalKeycloakAuthenticator
Vendor:
Michael Kelly
Software:
DuoUniversalKeycloakAuthenticator
Software CPE:
cpe:2.3:a:instipod:duouniversalkeycloakauthenticator:*:*:*:*:*:*:*:*
Website:
https://github.com/instipod
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU139159 - Deserialization of Untrusted Data CVE-2026-54512 |
CWE-502 | High | 1.1.2 | 22.07.2026 |
SB2026072278 SB2026072282 SB2026072283 and 26 more |
||
| #VU139158 - Incomplete List of Disallowed Inputs CVE-2026-54513 |
CWE-184 | High | 1.1.2 | 22.07.2026 |
SB2026072278 SB2026072282 SB2026072283 and 28 more |
||
| #VU84811 - Exposure of sensitive information to an unauthorized actor CVE-2023-49594 |
CWE-200 | Medium | 1.0.8 | 27.12.2023 |
SB2023122732 |