CVE-2017-7474: Keycloak Keycloak-Node.js-Auth-Utils

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

Affected products

  • Keycloak Keycloak-Node.js-Auth-Utils: version 2.5.0 only; version 2.5.1 only; version 2.5.2 only; version 2.5.3 only; version 2.5.4 only; version 2.5.5 only; …

Published 2017-05-12. Last modified 2026-06-17.