CVE-2026-4874

A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder. Successful exploitation allows the attacker to make HTTP requests from the Keycloak server’s network context, potentially probing internal networks or internal APIs, leading to information disclosure.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-26 08:16

Updated : 2026-06-26 08:16


NVD link : CVE-2026-4874

Mitre link : CVE-2026-4874

CVE.ORG link : CVE-2026-4874


JSON object : View

Products Affected

redhat

  • build_of_keycloak
  • jboss_enterprise_application_platform_expansion_pack
  • single_sign-on
  • jboss_enterprise_application_platform
CWE
CWE-918

Server-Side Request Forgery (SSRF)