CVE-2026-4634 Details
Description
A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a Denial of Service (DoS) for the Keycloak server.
A denial-of-service vulnerability has been identified in Keycloak. An unauthenticated attacker can exploit this issue by sending a POST request with an excessively long scope parameter to the OpenID Connect token endpoint. This exploitation leads to high resource consumption and extended processing times, causing a denial-of-service condition on the Keycloak server.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1050 | Excessive Platform Resource Consumption within a Loop | redhat-SADP |
| CWE-1050 | Excessive Platform Resource Consumption within a Loop | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat build of keycloak | 26.2 26.2.15 26.4 26.4.11 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2026 | Initial Analysis | [email protected] |
| Apr 2, 2026 | CVE Modified | [email protected] |
| Apr 2, 2026 | CVE Modified | [email protected] |
| Apr 2, 2026 | New CVE Received | [email protected] |