CVE-2026-1180: Red Hat Build Of Keycloak
Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using private_key_jwt. The issue allows a client to specify an arbitrary jwks_uri, which Keycloak then retrieves without validating the destination. This enables attackers to coerce the Keycloak server into making HTTP requests to internal or restricted network resources. As a result, attackers can probe internal services and cloud metadata endpoints, creating an information disclosure and reconnaissance risk.
Affected products
- Red Hat Red Hat Build Of Keycloak
- Red Hat Red Hat Build Of Keycloak 26.4: before 26.4.11-1 (fixed in 26.4.11-1); before 26.4-14 (fixed in 26.4-14)
- Red Hat Red Hat Build Of Keycloak 26.4.11
- Red Hat Red Hat JBoss Enterprise Application Platform 8
- Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat Red Hat Single Sign-On 7
Published 2026-01-20. Last modified 2026-06-17.