Known vulnerabilities in DuoUniversalKeycloakAuthenticator 1.1.0
Vendor:
Michael Kelly
Software:
DuoUniversalKeycloakAuthenticator
Version:
1.1.0
Software CPE:
cpe:2.3:a:instipod:duouniversalkeycloakauthenticator:*:*:*:*:*:*:*:*
Website:
https://github.com/instipod
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Vulnerabilities by Severity
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU139159 - Deserialization of Untrusted Data CVE-2026-54512 |
CWE-502 | High | 1.1.2 | 22.07.2026 |
SB2026072278 SB2026072282 SB2026072283 and 27 more |
||
| #VU139158 - Incomplete List of Disallowed Inputs CVE-2026-54513 |
CWE-184 | High | 1.1.2 | 22.07.2026 |
SB2026072278 SB2026072282 SB2026072283 and 29 more |