CVE-2026-18209: A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to p
A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is configured with a wildcard redirect URI, an attacker can use this to inject duplicate security parameters into the login response. If a client application is not configured correctly, it might trust the attacker's injected data instead of the real security information from Keycloak, leading to session fixation or account confusion.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-18209
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-182090.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18209 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for keycloak-services component of
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-18208: A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. …nvd · 2026-07-31
- lowCVE-2026-18206: A flaw was found in the keycloak-services component of Keycloak, which provides identity and a…nvd · 2026-07-31
- mediumCVE-2026-17059: A flaw was found in the role-users endpoint of the keycloak-services library, which is the cor…nvd · 2026-07-24
- mediumCVE-2026-16104: A flaw was found in the authentication configuration endpoint of the keycloak-services compone…nvd · 2026-07-17
- mediumCVE-2026-16103: A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete f…nvd · 2026-07-17
- mediumCVE-2026-16089: A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue oc…nvd · 2026-07-17
More from NVD Recent CVEs
- unknownCVE-2026-55735: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticat…2026-08-01
- unknownCVE-2026-55734: Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guar…2026-08-01
- unknownCVE-2026-55733: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- unknownCVE-2026-54894: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01