CVE-2026-1180: Red Hat Build Of Keycloak

Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using private_key_jwt. The issue allows a client to specify an arbitrary jwks_uri, which Keycloak then retrieves without validating the destination. This enables attackers to coerce the Keycloak server into making HTTP requests to internal or restricted network resources. As a result, attackers can probe internal services and cloud metadata endpoints, creating an information disclosure and reconnaissance risk.

Affected products

  • Red Hat Red Hat Build Of Keycloak
  • Red Hat Red Hat Build Of Keycloak 26.4: before 26.4.11-1 (fixed in 26.4.11-1); before 26.4-14 (fixed in 26.4-14)
  • Red Hat Red Hat Build Of Keycloak 26.4.11
  • Red Hat Red Hat JBoss Enterprise Application Platform 8
  • Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
  • Red Hat Red Hat Single Sign-On 7

Published 2026-01-20. Last modified 2026-06-17.