CVE-2017-7474: Keycloak Keycloak-Node.js-Auth-Utils
Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.
It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.
Affected products
- Keycloak Keycloak-Node.js-Auth-Utils: version 2.5.0 only; version 2.5.1 only; version 2.5.2 only; version 2.5.3 only; version 2.5.4 only; version 2.5.5 only; …
Published 2017-05-12. Last modified 2026-06-17.