Server-Side Request Forgery (SSRF) in Keycloak - CVE-2026-4874
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform server-side request forgery.
The vulnerability exists due to improper control of outbound requests in the OIDC token endpoint when manipulating token endpoint configuration. A remote attacker can manipulate the OIDC token endpoint to perform server-side request forgery.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-4874
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.3