Memory leak in Keycloak - CVE-2026-18212

 

Memory leak in Keycloak - CVE-2026-18212

Published: September 18, 2026


Vulnerability identifier: #VU150839
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-18212
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to missing release of memory after effective lifetime in the custom DEFLATE compression and decompression helpers of the SAML Redirect Binding implementation when processing repeated malformed SAML requests. A remote attacker can send repeated malformed SAML requests to cause a denial of service.


Affected software

Keycloak

How to mitigate CVE-2026-18212

Install security update from vendor's website.

Keycloak - update to 26.7.4

External References

Related Security Bulletins