CVE-2026-0976: Red Hat Build Of Keycloak

Low severity, CVSS 3.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A remote attacker can craft requests to mask path segments, potentially bypassing proxy-level path filtering. This could expose administrative or sensitive endpoints that operators believe are not externally reachable.

Affected products

  • Red Hat Red Hat Build Of Keycloak
  • Red Hat Red Hat JBoss Enterprise Application Platform 8
  • Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack

Published 2026-01-15. Last modified 2026-08-09.