HIGH7.5
GHSA-h4wv-g838-66g3
Keycloak: Application-Level DoS via Scope Processing
Quick fix
GHSA-h4wv-g838-66g3 — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.
# pom.xml: bump <version>26.5.7</version> for org.keycloak:keycloak-servicesDetails
A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a Denial of Service (DoS) for the Keycloak server.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.keycloak:keycloak-services
Introduced in:
0Fixed in: 26.5.7Fix
# pom.xml: bump <version>26.5.7</version> for org.keycloak:keycloak-servicesReferences
- https://nvd.nist.gov/vuln/detail/CVE-2026-4634[ADVISORY]
- https://github.com/keycloak/keycloak/issues/47716[WEB]
- https://github.com/keycloak/keycloak/commit/b455ee4f28abb6f2120aff72fd179589cc5267a0[WEB]
- https://access.redhat.com/errata/RHSA-2026:6475[WEB]
- https://access.redhat.com/errata/RHSA-2026:6476[WEB]
- https://access.redhat.com/errata/RHSA-2026:6477[WEB]
- https://access.redhat.com/errata/RHSA-2026:6478[WEB]
- https://access.redhat.com/security/cve/CVE-2026-4634[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2450250[WEB]
- https://github.com/keycloak/keycloak[PACKAGE]