Executive brief
Keycloak, a popular open-source identity and access management solution, is affected by a security flaw that could allow an authenticated user to perform unauthorized network requests. By manipulating specific session parameters, an attacker can force the Keycloak server to connect to internal systems or APIs that are not normally accessible from the outside. This could lead to the exposure of sensitive internal information or help an attacker map out a company's private network.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in Keycloak's OIDC token endpoint. An authenticated attacker can exploit this by manipulating the 'client_session_host' parameter during refresh token requests. The vulnerability is triggered when a Keycloak client is configured to use the 'backchannel.logout.url' containing the 'application.session.host' placeholder. By supplying a malicious host value, the attacker forces the Keycloak server to initiate HTTP requests from its own network context. This can be used to probe internal network services or APIs that are otherwise unreachable. The issue is patched in versions 26.6.3 and 26.4.13.
Affected products
- Keycloak Keycloak >= 26.5.0, < 26.6.3
- Keycloak Keycloak < 26.4.13
Timeline
- 2026-03-26: advisory: Initial publication of GHSA-22rm-wp4x-v5cx
- 2026-03-26: disclosed: NVD publication date
- 2026-07-15: other: Last updated date