Open redirect in Keycloak - CVE-2026-3872
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper redirect URI validation in the OIDC authorization endpoint when processing redirect URIs containing a ..;/ path traversal sequence and using a wildcard allowed path. A remote user can control another path on the same web server and bypass the allowed redirect URI path to disclose sensitive information.
User interaction is required.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-3872
Red Hat build of Keycloak - addressed in versions 26.2.15, 26.4.11