CVE-2026-4874 identifies a Server-Side Request Forgery (SSRF) vulnerability in Keycloak, allowing an authenticated attacker to manipulate the client_session_host parameter during refresh token requests. This flaw specifically occurs when a Keycloak client is configured to use backchannel.logout.url with the application.session.host placeholder, indicating high attack complexity. Successful exploitation could lead to information disclosure by enabling HTTP requests to internal networks from the Keycloak server. The vulnerability has a CVSS 3.1 score of 3.1 (LOW), reflecting its limited impact and specific prerequisites. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:* | ||
8.0.0CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.