CVE-2020-10758: Red Hat Keycloak

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.

Affected products

  • Red Hat Keycloak: before 11.0.1 (fixed in 11.0.1)
  • Red Hat Openshift Application Runtimes: affected versions not specified; version 1.0 only
  • Red Hat Single Sign-On: affected versions not specified; version 7.0 only; version 7.4 only

Published 2020-09-16. Last modified 2026-06-17.