Executive brief
Keycloak, an open-source identity and access management solution, contains a flaw in how it handles encrypted login requests. An attacker could bypass security policies to submit unauthorized data during the login process, potentially compromising the integrity of user authentication. While existing security controls like redirect allowlists provide some protection, this issue allows for the submission of unsigned data that should otherwise be rejected.
Technical details
An improper verification of cryptographic signatures (CWE-347) exists in Keycloak's OIDC request object processing. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may decrypt the content and process it as raw JSON without enforcing the configured 'requestObjectSignatureAlg' policy. This allows an attacker to bypass mandatory signing requirements (such as RS256) by wrapping unsigned claims in a JWE envelope. The vulnerability violates OIDC Core and FAPI requirements, though impact is partially mitigated by redirect URI allowlists. As of the advisory, no patch is explicitly confirmed for version 26.6.4.
Affected products
- Keycloak Keycloak <= 26.6.4
- Red Hat Red Hat Build of Keycloak -
Timeline
- 2026-05-28: disclosed: Vulnerability reported and GHSA published
- 2026-05-28: advisory: NVD and Red Hat advisories published