Open redirect in Keycloak - CVE-2026-7504
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect users to unauthorized URLs.
The vulnerability exists due to improper URL validation in Keycloak\'s redirect URI validation logic when processing a malicious redirect URL containing multiple @ characters in the user-info component. A remote attacker can send a crafted redirect request to redirect users to unauthorized URLs.
User interaction is required, and only clients configured with a wildcard (*) in the Valid Redirect URIs field are affected.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-7504
Red Hat build of Keycloak - addressed in versions 26.2.16, 26.4.12