CVE-2020-1727: Red Hat Keycloak
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.
Affected products
- Red Hat Keycloak: before 9.0.2 (fixed in 9.0.2)
Published 2020-06-22. Last modified 2026-06-17.