CVE-2026-2575 describes a denial-of-service vulnerability in Keycloak, allowing an unauthenticated remote attacker to disrupt service availability. This flaw occurs when the server fails to enforce size limits during DEFLATE decompression of a highly compressed SAMLRequest, leading to an OutOfMemoryError and process termination. Rated Medium severity (CVSS 5.3), the attack has low complexity, requires no authentication or user interaction, and directly impacts the availability of the service. Currently, there is no known public exploit code, evidence of active exploitation, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 26.4, < 26.4.10CPE matchmatch criteria | cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.