CVE-2026-103884
Received Received - Intake

X.509 Client Certificate Path Traversal in Keycloak

Vulnerability report for CVE-2026-103884, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: redhat-SADP

Description

A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat keycloak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a flaw in Keycloak's X.509 client certificate authenticator. When CRL Distribution Point checking is enabled, the server fails to validate file paths in client certificates properly. Attackers can exploit this by providing a specially crafted certificate to read sensitive local files or cause memory exhaustion by loading very large files, leading to information disclosure or system crashes.

Detection Guidance

To detect this vulnerability, inspect Keycloak server logs for unusual file access attempts or memory exhaustion errors. Check if CRL Distribution Point checking is enabled in the server configuration. Monitor for certificates with suspicious file paths in CRL Distribution Points.

Impact Analysis

An attacker could exploit this to read sensitive files on the server, leak metadata, or crash the system by consuming excessive memory. This requires the server to have non-default CRL checking configurations enabled.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles or HIPAA's confidentiality requirements. Information disclosure or system crashes may also impact compliance with availability and integrity standards.

Mitigation Strategies

Disable CRL Distribution Point checking in Keycloak if enabled. Ensure path normalization and containment checks are applied to all certificate inputs. Update Keycloak to the latest version if a patch is available. Restrict file system permissions for the Keycloak process.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103884. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart