CVE-2026-7307
published 2026-05-19CVE-2026-7307: A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML)…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.74%
50.6th percentile
A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | build_of_keycloak | >= 26.4 < 26.4.12 | 26.4.12 |
| rhbk | keycloak-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Keycloak on Red Hat SAML Endpoint improper validation of syntactic correctness of input (Nessus ID 316461 / WID-SEC-2026-1612)
vuldb·2026-05-23·CVSS 7.5
CVE-2026-7307 [HIGH] Keycloak on Red Hat SAML Endpoint improper validation of syntactic correctness of input (Nessus ID 316461 / WID-SEC-2026-1612)
A vulnerability classified as problematic has been found in Keycloak on Red Hat. Affected by this issue is some unknown functionality of the component SAML Endpoint. Performing a manipulation results in improper validation of syntactic correctness of input.
This vulnerability is cataloged as CVE-2026-7307. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
GHSA-p5mv-gj8j-xqgf: A flaw was found in Keycloak
ghsa_unreviewed·2026-05-19
CVE-2026-7307 [HIGH] CWE-1286 GHSA-p5mv-gj8j-xqgf: A flaw was found in Keycloak
A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.
GHSA
Keycloak: Denial of Service via specially crafted SAML input
ghsa·2026-05-19
CVE-2026-7307 [HIGH] CWE-1286 Keycloak: Denial of Service via specially crafted SAML input
Keycloak: Denial of Service via specially crafted SAML input
A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.
Red Hat
keycloak: Keycloak: Denial of Service via specially crafted SAML input
vendor_redhat·2026-05-19·CVSS 7.5
CVE-2026-7307 [HIGH] CWE-1286 keycloak: Keycloak: Denial of Service via specially crafted SAML input
keycloak: Keycloak: Denial of Service via specially crafted SAML input
A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.
Statement: This is a High severity denial of service vulnerability in Keycloak. An unauthenticated attacker with network access can send specially crafted XML input to the SAML endpoint, causing high CPU utilization and worker thread exhaustion, which renders the Keycloak server unavailable. This directly impacts the availability of Keycloak instances where the SAML protocol is enabled.
Mitigation: To mitigat
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2026:19594https://access.redhat.com/errata/RHSA-2026:19595https://access.redhat.com/errata/RHSA-2026:19596https://access.redhat.com/errata/RHSA-2026:19597https://access.redhat.com/security/cve/CVE-2026-7307https://bugzilla.redhat.com/show_bug.cgi?id=2476526https://access.redhat.com/errata/RHSA-2026:19594https://access.redhat.com/errata/RHSA-2026:19595https://access.redhat.com/errata/RHSA-2026:19596https://access.redhat.com/errata/RHSA-2026:19597https://access.redhat.com/security/cve/CVE-2026-7307https://bugzilla.redhat.com/show_bug.cgi?id=2476526https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7307.json
2026-05-19
Published