HIGH7.5
GHSA-p5mv-gj8j-xqgf
Keycloak: Denial of Service via specially crafted SAML input
Quick fix
GHSA-p5mv-gj8j-xqgf — org.keycloak:keycloak-saml-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>26.6.2</version> for org.keycloak:keycloak-saml-coreDetails
A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.keycloak:keycloak-saml-core
Introduced in:
0Fixed in: 26.6.2Fix
# pom.xml: bump <version>26.6.2</version> for org.keycloak:keycloak-saml-coreReferences
- https://nvd.nist.gov/vuln/detail/CVE-2026-7307[ADVISORY]
- https://github.com/keycloak/keycloak/pull/49119[WEB]
- https://github.com/keycloak/keycloak/commit/be84d28ce4c69c038d542f11405d5ede1d61f4a9[WEB]
- https://access.redhat.com/errata/RHSA-2026:19594[WEB]
- https://access.redhat.com/errata/RHSA-2026:19595[WEB]
- https://access.redhat.com/errata/RHSA-2026:19596[WEB]
- https://access.redhat.com/errata/RHSA-2026:19597[WEB]
- https://access.redhat.com/security/cve/CVE-2026-7307[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2476526[WEB]
- https://github.com/keycloak/keycloak[PACKAGE]
- https://github.com/keycloak/keycloak/releases/tag/26.6.2[WEB]