Technology · Maven
org.keycloak:keycloak-core (Maven) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 56 vulnerabilities in org.keycloak:keycloak-core (Maven): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-4028, was published on 18 February 2025.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest org.keycloak:keycloak-core (Maven) vulnerabilities
- CVE-2024-4028: Keycloak allows cross-site scripting (XSS)lowCVSS 3.1EPSS 0.3%
- CVE-2024-10039: Keycloak mTLS Authentication Bypass via Reverse Proxy TLS TerminationlowCVSS 3.1
- CVE-2023-6841: Keycloak Denial of Service vulnerabilitylowCVSS 3.1EPSS 0.7%
- CVE-2024-7260: Keycloak Open Redirect vulnerabilitylowCVSS 3.1EPSS 0.6%
- Duplicate Advisory: Keycloak Uses a Key Past its Expiration DatelowCVSS 3.1
- Duplicate Advisory: Keycloak: Leak of configured LDAP bind credentialslowCVSS 3.1
- Duplicate Advisory: Keycloak DoS via account lockoutlowCVSS 3.1
- CVE-2023-6927: keycloak-core: open redirect via "form_post.jwt" JARM response modelowCVSS 3.1EPSS 1.1%
- CVE-2023-4918: Keycloak vulnerable to Plaintext Storage of User PasswordlowCVSS 3.1EPSS 0.6%
- CVE-2023-0105: Keycloak: Impersonation and lockout possible through incorrect handling of email trustlowCVSS 3.1EPSS 0.7%
- CVE-2023-1664: Keycloak Untrusted Certificate Validation vulnerabilitylowCVSS 3.1EPSS 0.4%
- Duplicate Advisory: Keycloak vulnerable to untrusted certificate validationlowCVSS 3.1
- Duplicate Advisory: Keycloak allows impersonation and lockout due to email trust not being handled correctlylowCVSS 3.1
- CVE-2023-0091: Keycloak has lack of validation of access token on client registrations endpointlowCVSS 3.1EPSS 0.5%
- Duplicate Advisory: Keycloak vulnerable to Cross-Site Scripting (XSS)lowCVSS 3.1
- Duplicate Advisory: Keycloak user may register themselves with same email ID of any existing userlowCVSS 3.1
- CVE-2021-3856: Keycloak has Files or Directories Accessible to External PartieslowCVSS 3.1EPSS 1.1%
- CVE-2021-3632: Keycloak allows anyone to register new security device or key for any user by using WebAuthn password-less login flowlowCVSS 3.1EPSS 1.1%
- CVE-2022-0225: Keycloak XSS via use of malicious payload as group name when creating new group from admin consolelowCVSS 3.1EPSS 3.1%
- CVE-2020-35509: Keycloak vulnerable to Improper Certificate ValidationlowCVSS 3.1EPSS 0.3%
- CVE-2020-27838: Keycloak discloses information without authenticationlowCVSS 3.1EPSS 17.9%
- CVE-2020-10770: Keycloak vulnerable to Server-Side Request ForgerylowCVSS 3.1EPSS 69.7%
- CVE-2020-1698: Keycloak leaks sensitive information in logged exceptionslowCVSS 3.1EPSS 0.4%
- CVE-2020-1724: Keycloak Insufficient Session ExpirylowCVSS 3.1EPSS 0.8%
- CVE-2020-10686: Keycloak users may be able to remove MFA from other users' deviceslowCVSS 3.1EPSS 0.7%
Most severe org.keycloak:keycloak-core (Maven) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2020-10770: Keycloak vulnerable to Server-Side Request ForgerylowCVSS 3.1EPSS 69.7%
- CVE-2021-20323: Cross-site Scripting in KeycloaklowCVSS 3.1EPSS 37.3%
- CVE-2020-27838: Keycloak discloses information without authenticationlowCVSS 3.1EPSS 17.9%
- CVE-2022-0225: Keycloak XSS via use of malicious payload as group name when creating new group from admin consolelowCVSS 3.1EPSS 3.1%
- CVE-2020-1714: Improper Input Validation in KeycloaklowCVSS 3.1EPSS 2.6%
- CVE-2018-10912: Moderate severity vulnerability that affects org.keycloak:keycloak-corelowCVSS 3.1EPSS 1.3%
- CVE-2020-1731: Predictable password in KeycloaklowCVSS 3.1EPSS 1.3%
- CVE-2021-20195: keycloak Self Stored Cross-site Scripting vulnerabilitylowCVSS 3.1EPSS 1.3%
- CVE-2019-10170: Privilege Defined With Unsafe Actions in KeycloaklowCVSS 3.1EPSS 1.1%
- CVE-2021-3632: Keycloak allows anyone to register new security device or key for any user by using WebAuthn password-less login flowlowCVSS 3.1EPSS 1.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/org-keycloak-keycloak-core.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "org.keycloak:keycloak-core (Maven) vulnerabilities", https://junglewise.ai/threats/technologies/org-keycloak-keycloak-core, 27 September 2026.