CVE-2026-7307 Details
Description
A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.
A denial-of-service vulnerability has been identified in Keycloak. It allows remote, unauthenticated attackers to send specially crafted XML to the SAML endpoint. This malicious input can lead to high CPU usage and exhaustion of worker threads, causing the Keycloak server to become unavailable. The vulnerability affects all Keycloak versions on Linux.
To mitigate this vulnerability, restrict network access to the Keycloak SAML endpoint from untrusted sources. Implement firewall rules to limit inbound connections to the Keycloak service port from untrusted networks. If SAML is not needed, consider disabling it to reduce the attack surface. These changes may require a restart or reload of the Keycloak service.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1286 | Improper Validation of Syntactic Correctness of Input | redhat-SADP |
| CWE-1286 | Improper Validation of Syntactic Correctness of Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat build of keycloak | >= 26.4, < 26.4.12 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | New CVE Received | [email protected] |