Memory leak in Keycloak - CVE-2026-18212
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of memory after effective lifetime in the custom DEFLATE compression and decompression helpers of the SAML Redirect Binding implementation when processing repeated malformed SAML requests. A remote attacker can send repeated malformed SAML requests to cause a denial of service.