CVE-2018-10894: Red Hat Keycloak

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

Affected products

  • Red Hat Keycloak: version 3.4.3 only
  • Red Hat Single Sign-On: version 7.2 only

Published 2018-08-01. Last modified 2026-06-17.