Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fwhw-chw4-gh37 | Keycloak Server-Side Request Forgery (SSRF) vulnerability |
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Keycloak’s CIBA feature where insufficient validation of client-configured backchannel notification endpoints could allow blind server-side requests to internal services. | DO NOT USE THIS CANDIDATE NUMBER. After further review by the Keycloak project and Red Hat, the reported SSRF via client registration/backchannel notification URIs was determined not to constitute a security vulnerability. The reported behavior is expected administrator-controlled functionality, and Keycloak provides documented mitigations through Client Policies, including the Secure Client URIs Pattern executor. Therefore, this CVE has been rejected. |
| Title | Keycloak: blind server-side request forgery (ssrf) via ciba backchannel notification endpoint in keycloak | keycloak: Blind Server-Side Request Forgery (SSRF) via CIBA Backchannel Notification Endpoint in Keycloak |
| CPEs | ||
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| Metrics |
ssvc
|
Mon, 02 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 02 Feb 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Keycloak’s CIBA feature where insufficient validation of client-configured backchannel notification endpoints could allow blind server-side requests to internal services. | |
| Title | Keycloak: blind server-side request forgery (ssrf) via ciba backchannel notification endpoint in keycloak | |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:/a:redhat:build_keycloak: | |
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: REJECTED
Assigner: redhat
Published:
Updated: 2026-07-24T14:07:33.181Z
Reserved: 2026-01-28T08:08:15.419Z
Link: CVE-2026-1518
Updated:
Status : Deferred
Published: 2026-02-02T08:16:06.217
Modified: 2026-06-17T10:15:59.033
Link: CVE-2026-1518
OpenCVE Enrichment
Updated: 2026-04-18T00:45:32Z
Github GHSA