← Browse

CVE-2026-18209

Low

No strong exploitation signal.

CVSS base
3.4 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N
EPSS — probability of exploitation (30 days)
0.2%
14.3th percentile
CISA KEV
Not listed
Weakness / dates
CWE-1288
Published 2026-07-31 · modified 2026-09-16

CVSS breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N

Attack VectorNNetwork
Attack ComplexityHHigh
Privileges RequiredNNone
User InteractionRRequired
ScopeCChanged
ConfidentialityNNone
IntegrityLLow
AvailabilityNNone

Timeline

Description

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is configured with a wildcard redirect URI, an attacker can use this to inject duplicate security parameters into the login response. If a client application is not configured correctly, it might trust the attacker's injected data instead of the real security information from Keycloak, leading to session fixation or account confusion.

Affected

redhat

References

Official: NVD · CVE.org