CVE-2026-4874
published 2026-03-26CVE-2026-4874: A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter…
PriorityP415low3.1CVSS 3.1
AVNACHPRLUINSUCLINAN
EPSS
0.29%
21.5th percentile
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder. Successful exploitation allows the attacker to make HTTP requests from the Keycloak server’s network context, potentially probing internal networks or internal APIs, leading to information disclosure.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
ghsa·2026-03-26
CVE-2026-4874 [LOW] CWE-918 Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder. Successful exploitation allows the attacker to make HTTP requests from the Keycloak server’s network context, potentially probing internal networks or internal APIs, leading to information disclosure.
OSV
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
osv·2026-03-26
CVE-2026-4874 [LOW] Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder. Successful exploitation allows the attacker to make HTTP requests from the Keycloak server’s network context, potentially probing internal networks or internal APIs, leading to information disclosure.
Red Hat
org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: Keycloak: Server-Side Request Forgery via OIDC token endpoint manipulation
vendor_redhat·2026-03-26·CVSS 3.1
CVE-2026-4874 [LOW] CWE-918 org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: Keycloak: Server-Side Request Forgery via OIDC token endpoint manipulation
org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: Keycloak: Server-Side Request Forgery via OIDC token endpoint manipulation
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder. Successful exploitation allows the attacker to make HTTP requests from the Keycloak server’s network context, potentially probing internal networks or internal APIs, leading to information disclosure.
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_sess
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-4366 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-4366 [HIGH] CVE-2026-4366 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4366 :
JBoss EAP vulnerability analysis and mitigation
A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. As a result, sensitive internal services such as cloud metadata endpoints could be accessed. This issue may lead to information disclosure and enable attackers to map internal network infrastructure.
Source : NVD
## 5.8
Score
Published March 18, 2026
Severity MEDIUM
CNA Score 5.8
Affected Technologies
JBoss EAP
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitati
Wiz
CVE-2026-4874 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.4
CVE-2026-4874 [HIGH] CVE-2026-4874 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4874 :
Java vulnerability analysis and mitigation
client_session_host
backchannel.logout.url
application.session.host
Source : NVD
## 3.1
Score
Published March 26, 2026
Severity LOW
CNA Score 3.1
Affected Technologies
Java
Keycloak
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
keycloak-fips-26.5
cpe:2.3:a:redhat:jboss_enterprise_application_platform
Sources
Chainguard Has Fix Added at: Apr 05, 2026
Maven Severity LOW No Fix Added at: Mar 29, 2026
MinimOS Severity LOW Has Fix Added at: Apr 02, 2026
Linux Severity LOW No Fix Added at: Apr 02, 2026
Windows Severity LOW No Fix Added at: Apr 0
Bugzilla
CVE-2026-4874 org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: Keycloak: Server-Side Request Forgery via OIDC token endpoint manipulation
bugzilla·2026-03-26·CVSS 3.1
CVE-2026-4874 [LOW] CVE-2026-4874 org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: Keycloak: Server-Side Request Forgery via OIDC token endpoint manipulation
CVE-2026-4874 org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: Keycloak: Server-Side Request Forgery via OIDC token endpoint manipulation
Blind SSRF in Keycloak’s OIDC token endpoint allows an authenticated attacker to control the client_session_host parameter during refresh token requests, which is then stored in the client session. When a client is configured with backchannel.logout.url using the application.session.host placeholder, Keycloak substitutes this attacker‑controlled value and issues a server‑side HTTP POST to the resulting URL on logout. This lets the attacker make HTTP requests from the Keycloak server’s network context, potentially probing internal networks, cloud metadata services, or internal APIs that are not externally reachable. Exploitation require
2026-03-26
Published