LOW3.8
GHSA-fjf4-6f34-w64q
Keycloak: Missing Check on Disabled Client for Docker Registry Protocol
Details
A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administratively disabled. This means that turning the client “Enabled” setting to OFF does not fully prevent access. As a result, previously valid credentials can still be used to obtain authentication tokens. This weakens administrative controls and could allow unintended access to container registry resources.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.keycloak:keycloak-services
Introduced in:
0No fixed version published yet for org.keycloak:keycloak-services (maven). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-2733[ADVISORY]
- https://github.com/keycloak/keycloak/issues/46462[WEB]
- https://github.com/keycloak/keycloak/commit/743ac24081b2c6da36aac3775147ec5b80c2861e[WEB]
- https://access.redhat.com/errata/RHSA-2026:3947[WEB]
- https://access.redhat.com/errata/RHSA-2026:3948[WEB]
- https://access.redhat.com/security/cve/CVE-2026-2733[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2440895[WEB]
- https://github.com/keycloak/keycloak[PACKAGE]