CVE-2026-103884
Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.
| CWE | CWE-22 |
| Vendor | red hat |
| Product | red hat build of keycloak |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for red hat red hat build of keycloak
Be the first to know when new medium vulnerabilities affecting red hat red hat build of keycloak are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
High
Affected Versions
Red Hat / Red Hat Build of Keycloak
All versions affected Red Hat / Red Hat Build of Keycloak
All versions affected Red Hat / Red Hat Single Sign-On 7
All versions affected References
Credits
Red Hat would like to thank Robin Marchand for reporting this issue.