Executive brief
A reported security issue in Keycloak, an identity and access management solution, was determined to be expected behavior rather than a vulnerability. The report suggested that administrators could configure certain notification addresses to trigger internal network requests, but this is a standard administrative function. Organizations using Keycloak are not at increased risk from this report, as existing security controls already manage this functionality.
Technical details
A potential Server-Side Request Forgery (SSRF) was reported in Keycloak's Client Initiated Backchannel Authentication (CIBA) feature and client registration endpoints. The concern was that insufficient validation of backchannel notification URIs could allow the server to make requests to internal services. However, Red Hat and the Keycloak project determined this is expected behavior for authenticated administrators. Keycloak provides built-in mitigations for this behavior via Client Policies and the 'Secure Client URIs Pattern' executor, leading to the formal rejection of the CVE.
Affected products
- Red Hat Keycloak All versions (Rejected)
Timeline
- 2026-02-02: disclosed: Initial CVE publication
- 2026-07-24: other: CVE formally rejected by Red Hat and the Keycloak project