Improper Validation of Consistency within Input in Red Hat build of Keycloak - CVE-2026-9689
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a client application to process attacker-controlled OIDC response parameters.
The vulnerability exists due to HTTP parameter pollution in OIDC redirect URI processing when processing a crafted authorization URL. A remote attacker can craft an authorization URL with duplicate response parameters to cause a client application to process attacker-controlled OIDC response parameters.
Exploitation requires a broad redirect URI configuration, a client application that uses first-wins handling for duplicate query parameters, and user interaction to open the crafted URL.