CVE-2026-105301
Received Received - Intake

Keycloak X.509 Certificate Validation SSRF via Malicious CRL

Vulnerability report for CVE-2026-105301, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: redhat-SADP

Description

A flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management. The issue occurs when the server is configured to check certificate revocation using CRL Distribution Points or OCSP. An attacker can provide a specially crafted certificate that points to a malicious server, causing Keycloak to make unauthorized outbound requests to internal or external endpoints before the certificate is fully validated. This can lead to a blind server-side request forgery (SSRF) attack.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat keycloak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a blind Server-Side Request Forgery (SSRF) vulnerability in Keycloak's X.509 client-certificate authenticator. When configured to check certificate revocation via CRL Distribution Points or OCSP, Keycloak fetches URLs from untrusted client certificates before validating them. An attacker can craft a certificate with malicious URLs, causing Keycloak to make unauthorized outbound requests to internal or external endpoints.

Detection Guidance

To detect this vulnerability, monitor outbound HTTP requests from Keycloak servers configured with X.509 client-certificate authentication and CRLDP or OCSP checking. Check logs for unexpected connections to internal or external endpoints triggered by certificate validation. Use network monitoring tools like tcpdump or Wireshark to capture outbound traffic from Keycloak processes.

Impact Analysis

An attacker could exploit this to probe internal network resources, interact with restricted services, or perform unauthorized actions on your systems. The impact depends on your Keycloak configuration and network setup, but it enables blind SSRF attacks without authentication.

Compliance Impact

This vulnerability could lead to unauthorized data access or network probing, potentially violating confidentiality requirements in GDPR or HIPAA. Organizations using Keycloak with X.509 authentication and revocation checking may face compliance risks due to insufficient network access controls.

Mitigation Strategies

Disable CRL Distribution Points or OCSP revocation checking in Keycloak's X.509 authenticator configuration. If proxy-header cert-lookup is used, ensure proxy-trusted-addresses is properly configured. Upgrade to a patched version if available. Monitor for unusual outbound requests until mitigation is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105301. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart