Server-Side Request Forgery (SSRF) in Keycloak - CVE-2026-4366
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper handling of HTTP redirects in Keycloak client configuration request processing when processing certain client configuration requests. A remote attacker can cause the server to make unintended requests to internal or restricted resources to disclose sensitive information.
Cloud metadata endpoints may be accessible, and the issue may enable internal network infrastructure mapping.