CVE-2017-12158: Keycloak

Medium severity, CVSS 5.4. EPSS: 1% chance of exploitation in the next 30 days.

It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.

Affected products

  • Keycloak Keycloak: affected versions not specified
  • Red Hat Single Sign On: version 7.0 only; version 7.1 only

Published 2017-10-26. Last modified 2026-06-17.