ZeroHour

CVE-2026-4874

CVSS 3.1
3.1 low
EPSS
<1%p22
Published
()
Modified
Description

A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder. Successful exploitation allows the attacker to make HTTP requests from the Keycloak server’s network context, potentially probing internal networks or internal APIs, leading to information disclosure.

Vendors
redhat
Products
build of keycloak, jboss enterprise application platform, jboss enterprise application platform expansion pack, single sign-on
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.