Security Advisory

CVE-2026-4634

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-02 12:44:53
Last updated 2026-07-15 00:50:36
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a Denial of Service (DoS) for the Keycloak server.