Executive brief
Keycloak, an open-source identity and access management solution, is vulnerable to a security flaw that allows attackers to redirect users to malicious websites. This occurs when Keycloak is configured to use wildcards for valid redirect addresses, allowing an attacker to trick the system into sending a user to an unauthorized external domain. If successful, this could be used in phishing campaigns to steal user credentials or sensitive session information.
Technical details
An open redirect vulnerability exists in Keycloak's URL validation logic due to a discrepancy between Keycloak and the underlying Java URI implementation. When a redirect URL contains multiple '@' characters in the user-info component, the Java URI parser fails to correctly extract the user-info, leaving only the raw authority field. Keycloak's validation fails to detect this malformed component and falls back to a wildcard comparison, incorrectly permitting the redirect. This affects clients configured with a wildcard (*) in the 'Valid Redirect URIs' field. Exploitation requires a remote attacker to trick a user into clicking a specially crafted link. The issue is patched in Keycloak version 26.6.2 and various Red Hat build of Keycloak versions.
Affected products
- Keycloak Keycloak < 26.6.2
- Red Hat Red Hat build of Keycloak 26.4.x < 26.4.12, 26.2.x < 26.2.16
Timeline
- 2026-04-30: other: Bug reported to Red Hat Bugzilla
- 2026-05-19: disclosed: CVE-2026-7504 published
- 2026-05-19: advisory: GitHub Advisory GHSA-rp95-xpg9-c2cq published
- 2026-05-20: patched: Red Hat released security updates (RHSA-2026:19594, RHSA-2026:19597)