CVE-2024-10270: Red Hat Build Of Keycloak 24

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.

Affected products

  • Red Hat Red Hat Build Of Keycloak 24: before 24.0.9-1 (fixed in 24.0.9-1); before 24-18 (fixed in 24-18)
  • Red Hat Red Hat Build Of Keycloak 24.0.9
  • Red Hat Red Hat Build Of Keycloak 26.0: before 26.0.6-2 (fixed in 26.0.6-2); before 26.0-5 (fixed in 26.0-5); before 26.0-6 (fixed in 26.0-6)
  • Red Hat Red Hat Build Of Keycloak 26.0.6
  • Red Hat Red Hat JBoss Enterprise Application Platform 8
  • Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
  • Red Hat Red Hat Single Sign-On 7

Published 2024-11-25. Last modified 2026-09-21.