{"schema_version":1,"title":"org.keycloak:keycloak-parent (Maven) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 26 vulnerabilities in org.keycloak:keycloak-parent (Maven): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-1518, was published on 2 February 2026.","url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-parent","json_url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-parent.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/org-keycloak-keycloak-parent","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":26,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":2},"latest":[{"cve":"CVE-2026-1518","cvss":3.1,"epss":0.0024,"slug":"cve-2026-1518-keycloak-ssrf-in-client-registration-and-backchannel-notification","title":"Keycloak SSRF in client registration and backchannel notification URIs","severity":"low","exploited":false,"published_at":"2026-02-02T08:16:06.217+00:00","url":"https://junglewise.ai/threats/cve-2026-1518-keycloak-ssrf-in-client-registration-and-backchannel-notification"},{"cve":"CVE-2026-0707","cvss":5.3,"epss":0.0041,"slug":"cve-2026-0707-keycloak-permissive-authorization-header-parsing-bypass","title":"Keycloak permissive Authorization header parsing bypass","severity":"medium","exploited":false,"published_at":"2026-01-08T04:15:56.52+00:00","url":"https://junglewise.ai/threats/cve-2026-0707-keycloak-permissive-authorization-header-parsing-bypass"},{"cvss":3.1,"slug":"duplicate-advisory-keycloak-open-redirect-vulnerability-32d9749a","title":"Duplicate Advisory: Keycloak Open Redirect vulnerability","severity":"low","exploited":false,"published_at":"2023-12-19T00:30:21+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-keycloak-open-redirect-vulnerability-32d9749a"},{"cve":"CVE-2022-4137","cvss":3.1,"epss":0.0115,"slug":"cve-2022-4137-keycloak-cross-site-scripting-on-openid-connect-login-service","title":"Keycloak Cross-site Scripting on OpenID connect login service","severity":"low","exploited":false,"published_at":"2023-03-01T17:38:56+00:00","url":"https://junglewise.ai/threats/cve-2022-4137-keycloak-cross-site-scripting-on-openid-connect-login-service"},{"cve":"CVE-2022-3782","cvss":3.1,"epss":0.058,"slug":"cve-2022-3782-keycloak-vulnerable-to-path-traversal-via-double-url-encoding","title":"Keycloak vulnerable to path traversal via double URL encoding","severity":"low","exploited":false,"published_at":"2022-12-13T19:44:56+00:00","url":"https://junglewise.ai/threats/cve-2022-3782-keycloak-vulnerable-to-path-traversal-via-double-url-encoding"},{"cve":"CVE-2022-3916","cvss":3.1,"epss":0.0095,"slug":"cve-2022-3916-keycloak-vulnerable-to-session-takeover-with-oidc-offline","title":"Keycloak vulnerable to session takeover with OIDC offline refreshtokens","severity":"low","exploited":false,"published_at":"2022-12-13T19:44:33+00:00","url":"https://junglewise.ai/threats/cve-2022-3916-keycloak-vulnerable-to-session-takeover-with-oidc-offline"},{"cve":"CVE-2022-2256","cvss":3.1,"epss":0.0068,"slug":"cve-2022-2256-keycloak-vulnerable-to-stored-cross-site-scripting-xss-when","title":"Keycloak vulnerable to Stored Cross site Scripting (XSS) when loading default roles","severity":"low","exploited":false,"published_at":"2022-09-23T16:32:51+00:00","url":"https://junglewise.ai/threats/cve-2022-2256-keycloak-vulnerable-to-stored-cross-site-scripting-xss-when"},{"cve":"CVE-2022-2668","cvss":3.1,"epss":0.0095,"slug":"cve-2022-2668-keycloak-saml-javascript-protocol-mapper-uploading-of-scripts","title":"Keycloak SAML javascript protocol mapper: Uploading of scripts through admin console","severity":"low","exploited":false,"published_at":"2022-09-23T16:32:32+00:00","url":"https://junglewise.ai/threats/cve-2022-2668-keycloak-saml-javascript-protocol-mapper-uploading-of-scripts"},{"cve":"CVE-2021-3513","cvss":3.1,"epss":0.0078,"slug":"cve-2021-3513-incorrect-implementation-of-lockout-feature-in-keycloak","title":"Incorrect implementation of lockout feature in Keycloak","severity":"low","exploited":false,"published_at":"2022-08-23T00:00:17+00:00","url":"https://junglewise.ai/threats/cve-2021-3513-incorrect-implementation-of-lockout-feature-in-keycloak"},{"cve":"CVE-2019-14910","cvss":3.1,"epss":0.0105,"slug":"cve-2019-14910-keycloak-authentication-error","title":"Keycloak Authentication Error","severity":"low","exploited":false,"published_at":"2022-05-24T17:02:42+00:00","url":"https://junglewise.ai/threats/cve-2019-14910-keycloak-authentication-error"},{"cve":"CVE-2019-14909","cvss":3.1,"epss":0.0108,"slug":"cve-2019-14909-keycloak-authentication-error","title":"Keycloak Authentication Error","severity":"low","exploited":false,"published_at":"2022-05-24T17:02:40+00:00","url":"https://junglewise.ai/threats/cve-2019-14909-keycloak-authentication-error"},{"cve":"CVE-2017-12158","cvss":3,"epss":0.0102,"slug":"cve-2017-12158-keycloak-reflected-xss","title":"Keycloak Reflected XSS","severity":"low","exploited":false,"published_at":"2022-05-13T01:38:14+00:00","url":"https://junglewise.ai/threats/cve-2017-12158-keycloak-reflected-xss"},{"cve":"CVE-2017-12159","cvss":3,"epss":0.0271,"slug":"cve-2017-12159-keycloak-csrf-vulnerability","title":"Keycloak CSRF Vulnerability","severity":"low","exploited":false,"published_at":"2022-05-13T01:38:14+00:00","url":"https://junglewise.ai/threats/cve-2017-12159-keycloak-csrf-vulnerability"},{"cve":"CVE-2017-12160","cvss":3.1,"epss":0.0192,"slug":"cve-2017-12160-keycloak-oauth-implementation-error","title":"Keycloak Oauth Implementation Error","severity":"low","exploited":false,"published_at":"2022-05-13T01:23:16+00:00","url":"https://junglewise.ai/threats/cve-2017-12160-keycloak-oauth-implementation-error"},{"cve":"CVE-2018-14657","cvss":3.1,"epss":0.0116,"slug":"cve-2018-14657-keycloak-improper-bruteforce-detection","title":"Keycloak Improper Bruteforce Detection","severity":"low","exploited":false,"published_at":"2022-05-13T01:12:25+00:00","url":"https://junglewise.ai/threats/cve-2018-14657-keycloak-improper-bruteforce-detection"},{"slug":"reflected-xss-on-clients-registrations-endpoint-d8ffa613","title":"Reflected XSS on clients-registrations endpoint","severity":"info","exploited":false,"published_at":"2022-04-28T21:01:28+00:00","url":"https://junglewise.ai/threats/reflected-xss-on-clients-registrations-endpoint-d8ffa613"},{"cve":"CVE-2021-3461","cvss":3.1,"epss":0.003,"slug":"cve-2021-3461-keycloak-insufficient-session-expiration","title":"Keycloak insufficient session expiration","severity":"low","exploited":false,"published_at":"2022-04-03T00:01:01+00:00","url":"https://junglewise.ai/threats/cve-2021-3461-keycloak-insufficient-session-expiration"},{"cve":"CVE-2020-1718","cvss":3.1,"epss":0.01,"slug":"cve-2020-1718-improper-authentication-for-keycloak","title":"Improper Authentication for Keycloak","severity":"low","exploited":false,"published_at":"2022-02-09T00:59:32+00:00","url":"https://junglewise.ai/threats/cve-2020-1718-improper-authentication-for-keycloak"},{"cve":"CVE-2020-1717","cvss":3.1,"epss":0.0077,"slug":"cve-2020-1717-generation-of-error-message-containing-sensitive-information-in","title":"Generation of Error Message Containing Sensitive Information in Keycloak","severity":"low","exploited":false,"published_at":"2022-02-09T00:59:06+00:00","url":"https://junglewise.ai/threats/cve-2020-1717-generation-of-error-message-containing-sensitive-information-in"},{"cve":"CVE-2020-1725","cvss":3.1,"epss":0.0068,"slug":"cve-2020-1725-incorrect-authorization-in-keycloak","title":"Incorrect Authorization in keycloak","severity":"low","exploited":false,"published_at":"2022-02-09T00:58:52+00:00","url":"https://junglewise.ai/threats/cve-2020-1725-incorrect-authorization-in-keycloak"},{"cve":"CVE-2020-14366","cvss":3.1,"epss":0.0138,"slug":"cve-2020-14366-path-traversal","title":"Path Traversal","severity":"low","exploited":false,"published_at":"2022-02-09T00:58:03+00:00","url":"https://junglewise.ai/threats/cve-2020-14366-path-traversal"},{"cve":"CVE-2020-1694","cvss":3.1,"epss":0.0164,"slug":"cve-2020-1694-incorrect-permission-assignment-for-critical-resource-and","title":"Incorrect Permission Assignment for Critical Resource and Permissive List of Allowed Inputs in Keycloak","severity":"low","exploited":false,"published_at":"2022-02-09T00:57:02+00:00","url":"https://junglewise.ai/threats/cve-2020-1694-incorrect-permission-assignment-for-critical-resource-and"},{"cve":"CVE-2020-10758","cvss":3.1,"epss":0.0195,"slug":"cve-2020-10758-allocation-of-resources-without-limits-or-throttling-in-keycloak","title":"Allocation of Resources Without Limits or Throttling in Keycloak","severity":"low","exploited":false,"published_at":"2022-02-09T00:56:51+00:00","url":"https://junglewise.ai/threats/cve-2020-10758-allocation-of-resources-without-limits-or-throttling-in-keycloak"},{"cve":"CVE-2020-10748","cvss":3.1,"epss":0.0093,"slug":"cve-2020-10748-cross-site-scripting-in-keycloak","title":"Cross-site Scripting in Keycloak","severity":"low","exploited":false,"published_at":"2022-02-09T00:56:37+00:00","url":"https://junglewise.ai/threats/cve-2020-10748-cross-site-scripting-in-keycloak"},{"cve":"CVE-2020-1758","cvss":3.1,"epss":0.0091,"slug":"cve-2020-1758-improper-certificate-validation-and-improper-validation-of","title":"Improper Certificate Validation and Improper Validation of Certificate with Host Mismatch in Keycloak","severity":"low","exploited":false,"published_at":"2022-02-09T00:56:26+00:00","url":"https://junglewise.ai/threats/cve-2020-1758-improper-certificate-validation-and-improper-validation-of"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"com.liferay.portal:release.portal.bom (Maven)","slug":"com-liferay-portal-release-portal-bom","vulnerabilities":92,"url":"https://junglewise.ai/threats/technologies/com-liferay-portal-release-portal-bom"},{"name":"org.keycloak:keycloak-services (Maven)","slug":"org-keycloak-keycloak-services","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-services"},{"name":"org.keycloak:keycloak-core (Maven)","slug":"org-keycloak-keycloak-core","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-core"},{"name":"org.apache.struts:struts2-core (Maven)","slug":"org-apache-struts-struts2-core","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/org-apache-struts-struts2-core"},{"name":"net.mingsoft:ms-mcms (Maven)","slug":"net-mingsoft-ms-mcms","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/net-mingsoft-ms-mcms"},{"name":"com.thoughtworks.xstream:xstream (Maven)","slug":"com-thoughtworks-xstream-xstream","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/com-thoughtworks-xstream-xstream"},{"name":"com.jfinal:jfinal (Maven)","slug":"com-jfinal-jfinal","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/com-jfinal-jfinal"},{"name":"org.jenkins-ci.plugins:script-security (Maven)","slug":"org-jenkins-ci-plugins-script-security","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/org-jenkins-ci-plugins-script-security"},{"name":"org.apache.tomcat:tomcat (Maven)","slug":"org-apache-tomcat-tomcat","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/org-apache-tomcat-tomcat"},{"name":"com.liferay.portal:release.dxp.bom (Maven)","slug":"com-liferay-portal-release-dxp-bom","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/com-liferay-portal-release-dxp-bom"},{"name":"org.opencms:opencms-core (Maven)","slug":"org-opencms-opencms-core","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/org-opencms-opencms-core"},{"name":"com.fasterxml.jackson.core:jackson-databind (Maven)","slug":"com-fasterxml-jackson-core-jackson-databind","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/com-fasterxml-jackson-core-jackson-databind"}],"technology":{"hub":true,"name":"org.keycloak:keycloak-parent (Maven)","slug":"org-keycloak-keycloak-parent","vendor":{"name":"Maven","slug":"maven","url":"https://junglewise.ai/threats/vendors/maven"},"aliases":[],"homepage":"https://www.keycloak.org/","repo_url":"https://github.com/keycloak/keycloak","description":"The parent Maven project for Keycloak, an open-source identity and access management solution.","url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-parent"},"most_severe":[{"cve":"CVE-2026-0707","cvss":5.3,"epss":0.0041,"slug":"cve-2026-0707-keycloak-permissive-authorization-header-parsing-bypass","title":"Keycloak permissive Authorization header parsing bypass","severity":"medium","exploited":false,"published_at":"2026-01-08T04:15:56.52+00:00","url":"https://junglewise.ai/threats/cve-2026-0707-keycloak-permissive-authorization-header-parsing-bypass"},{"cve":"CVE-2022-3782","cvss":3.1,"epss":0.058,"slug":"cve-2022-3782-keycloak-vulnerable-to-path-traversal-via-double-url-encoding","title":"Keycloak vulnerable to path traversal via double URL encoding","severity":"low","exploited":false,"published_at":"2022-12-13T19:44:56+00:00","url":"https://junglewise.ai/threats/cve-2022-3782-keycloak-vulnerable-to-path-traversal-via-double-url-encoding"},{"cve":"CVE-2020-10758","cvss":3.1,"epss":0.0195,"slug":"cve-2020-10758-allocation-of-resources-without-limits-or-throttling-in-keycloak","title":"Allocation of Resources Without Limits or Throttling in Keycloak","severity":"low","exploited":false,"published_at":"2022-02-09T00:56:51+00:00","url":"https://junglewise.ai/threats/cve-2020-10758-allocation-of-resources-without-limits-or-throttling-in-keycloak"},{"cve":"CVE-2017-12160","cvss":3.1,"epss":0.0192,"slug":"cve-2017-12160-keycloak-oauth-implementation-error","title":"Keycloak Oauth Implementation Error","severity":"low","exploited":false,"published_at":"2022-05-13T01:23:16+00:00","url":"https://junglewise.ai/threats/cve-2017-12160-keycloak-oauth-implementation-error"},{"cve":"CVE-2020-1694","cvss":3.1,"epss":0.0164,"slug":"cve-2020-1694-incorrect-permission-assignment-for-critical-resource-and","title":"Incorrect Permission Assignment for Critical Resource and Permissive List of Allowed Inputs in Keycloak","severity":"low","exploited":false,"published_at":"2022-02-09T00:57:02+00:00","url":"https://junglewise.ai/threats/cve-2020-1694-incorrect-permission-assignment-for-critical-resource-and"},{"cve":"CVE-2020-14366","cvss":3.1,"epss":0.0138,"slug":"cve-2020-14366-path-traversal","title":"Path Traversal","severity":"low","exploited":false,"published_at":"2022-02-09T00:58:03+00:00","url":"https://junglewise.ai/threats/cve-2020-14366-path-traversal"},{"cve":"CVE-2021-20222","cvss":3.1,"epss":0.0119,"slug":"cve-2021-20222-code-injection-in-keycloak","title":"Code injection in keycloak","severity":"low","exploited":false,"published_at":"2021-05-13T22:29:51+00:00","url":"https://junglewise.ai/threats/cve-2021-20222-code-injection-in-keycloak"},{"cve":"CVE-2018-14657","cvss":3.1,"epss":0.0116,"slug":"cve-2018-14657-keycloak-improper-bruteforce-detection","title":"Keycloak Improper Bruteforce Detection","severity":"low","exploited":false,"published_at":"2022-05-13T01:12:25+00:00","url":"https://junglewise.ai/threats/cve-2018-14657-keycloak-improper-bruteforce-detection"},{"cve":"CVE-2022-4137","cvss":3.1,"epss":0.0115,"slug":"cve-2022-4137-keycloak-cross-site-scripting-on-openid-connect-login-service","title":"Keycloak Cross-site Scripting on OpenID connect login service","severity":"low","exploited":false,"published_at":"2023-03-01T17:38:56+00:00","url":"https://junglewise.ai/threats/cve-2022-4137-keycloak-cross-site-scripting-on-openid-connect-login-service"},{"cve":"CVE-2019-14909","cvss":3.1,"epss":0.0108,"slug":"cve-2019-14909-keycloak-authentication-error","title":"Keycloak Authentication Error","severity":"low","exploited":false,"published_at":"2022-05-24T17:02:40+00:00","url":"https://junglewise.ai/threats/cve-2019-14909-keycloak-authentication-error"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}