Keycloak
Vendor:
First CVE: Oct 26, 2017 · Active for 8 years
99
Total CVEs
More Total CVEs than 99% of tracked products
9.9
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Keycloak over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2017
8 years ago
Most Recent CVE
Mar 5, 2026
141 days ago
CVE Severity & Scoring
Keycloak99 CVEs
55%
34%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (5.1%)
Network93 (93.9%)
Unknown0 (0.0%)
Physical1 (1.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low82 (82.8%)
High17 (17.2%)
Unknown0 (0.0%)
User Interaction
None68 (68.7%)
Unknown0 (0.0%)
Required31 (31.3%)
Privileges Required
Low36 (36.4%)
High15 (15.2%)
None48 (48.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (99 CVEs).
99 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2020-10770MEDIUM A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacke | Dec 15, 2020 | 5.3 | 74 | NO | YES |
CVE-2021-20323MEDIUM A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. | Mar 25, 2022 | 6.1 | 52 | NO | YES |
CVE-2020-27838MEDIUM A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authenticat | Mar 8, 2021 | 6.5 | 41 | NO | YES |
CVE-2026-3047HIGH A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing | Mar 5, 2026 | 8.8 | 33 | NO | NO |
CVE-2022-3782CRITICAL keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to co | Jan 13, 2023 | 9.1 | 32 | NO | NO |
CVE-2021-4133HIGH A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administr | Jan 25, 2022 | 8.8 | 29 | NO | NO |
CVE-2021-20195CRITICAL A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to user-supplied data fields not b | May 28, 2021 | 9.6 | 29 | NO | NO |
CVE-2019-14910CRITICAL A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case | Dec 5, 2019 | 9.8 | 29 | NO | NO |
CVE-2020-1718HIGH A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application. | May 12, 2020 | 8.8 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (99 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
4.0% of CVEs· 97th percentile
ExploitDB
1 CVE
1.0% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (99 CVEs).
Media Mentions
Signals from CVEs in this product scope (99 CVEs).
Top CNAs Publishing CVEs For Keycloak
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.13 | 1 | 7.1 | 0.3% | 0 | 0 |
| 9.0.0 | 1 | 4.7 | 0.7% | 0 | 0 |
| 8.0.2 | 1 | 4.7 | 0.7% | 0 | 0 |
| 7.0.1 | 3 | 6.9 | 1.0% | 0 | 0 |
| 7.0.0 | 2 | 9.1 | 1.1% | 0 | 0 |
| 4.3.0 | 2 | 6.8 | 1.2% | 0 | 0 |
| 4.2.1 | 1 | 8.1 | 1.2% | 0 | 0 |
| 4.0.0 | 1 | 5.4 | 1.2% | 0 | 0 |
| 3.4.3 | 2 | 5.4 | 0.8% | 0 | 0 |
| 3.2.1 | 1 | 6.1 | 1.1% | 0 | 0 |
| 24.0.2 | 1 | 3.1 | 0.2% | 0 | 0 |
| 23.0.5 | 1 | 5.3 | 0.8% | 0 | 0 |
| 22.0.2 | 1 | 8.8 | 0.5% | 0 | 0 |
| 20.0.2 | 1 | 9.1 | 5.8% | 0 | 0 |
| 18.0.0 | 1 | 7.2 | 0.9% | 0 | 0 |
| 12.0.0 | 2 | 6.1 | 0.3% | 0 | 0 |
| 11.0.3 | 1 | 5.4 | 0.3% | 0 | 0 |
| 1.0.1 | 1 | 6.1 | 0.7% | 0 | 0 |
| 10.0.1 | 1 | 6.1 | 0.9% | 0 | 0 |