Server-Side Request Forgery (SSRF) in Keycloak - CVE-2026-1180
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform blind server-side request forgery.
The vulnerability exists due to improper handling of jwks_uri in Keycloak OIDC Dynamic Client Registration when processing dynamic client registration requests. A remote attacker can provide a jwks_uri value to perform blind server-side request forgery.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-1180
Red Hat build of Keycloak - update to 26.4.11