GHSA-jh7q-5mwf-qvhw
GitHub Security Advisory
Keycloak vulnerable to Server-Side Request Forgery
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter `request_uri`. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
Affected Packages
Maven
org.keycloak:keycloak-core
Affected versions:
0
(fixed in 13.0.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 28, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.