CVE-2023-6927: Red Hat Keycloak

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134.

Affected products

  • Red Hat Keycloak: affected versions not specified
  • Red Hat Single Sign-On: version 7.0 only

Published 2023-12-18. Last modified 2026-09-22.