Improper Validation of Syntactic Correctness of Input in Keycloak - CVE-2026-7307

 

Improper Validation of Syntactic Correctness of Input in Keycloak - CVE-2026-7307

Published: September 10, 2026


Vulnerability identifier: #VU148946
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-7307
CWE-ID: CWE-1286
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper validation of syntactic correctness of input in the SAML endpoint when processing specially crafted XML input. A remote attacker can send a specially crafted XML input to cause a denial of service.

The malicious input can cause high CPU usage and worker thread starvation, making the server unavailable.


Affected software

Keycloak
Red Hat build of Keycloak

How to mitigate CVE-2026-7307

Install security update from vendor's website.

Keycloak - update to 26.6.2
Red Hat build of Keycloak - addressed in versions 26.2.16, 26.4.12

External References

Related Security Bulletins