{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aredhatkeycloak/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-18212"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Keycloak"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-18212 describes a memory management vulnerability within the SAML Redirect Binding implementation of Keycloak. The defect resides in the application's custom DEFLATE compression and decompression helpers, which fail to correctly release native zlib memory after processing SAML payloads. Because this logic is executed during the handling of incoming SAML Redirect Binding requests, it is accessible to unauthenticated remote users. By repeatedly sending specially crafted or malformed SAML requests that trigger this compression routine, an attacker can induce a steady accumulation of native memory usage, eventually leading to exhaustion of the Java Virtual Machine (JVM) native memory. This results in a persistent denial of service condition for the affected Keycloak instance.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a complete denial of service for the Keycloak identity provider, preventing users from authenticating to any downstream applications or services integrated with the identity manager. This affects availability for organizations relying on Keycloak for Single Sign-On (SSO) and identity federation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize monitoring for anomalous spikes in SAML authentication traffic or high rates of malformed HTTP requests targeting SAML endpoints. Ensure Keycloak instances are updated to the vendor-provided patch version (when available) that remediates the native zlib memory leak. Monitor system-level metrics (e.g., resident set size and native memory allocation) for the Keycloak process to detect memory exhaustion patterns indicative of exploitation.\u003c/p\u003e\n","date_modified":"2026-09-16T15:50:57Z","date_published":"2026-09-16T15:50:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-keycloak-saml-dos/","summary":"An unauthenticated attacker can trigger a denial of service in Keycloak by sending repeated malformed SAML requests that cause native memory exhaustion due to improper zlib memory management.","title":"CVE-2026-18212 Keycloak Denial of Service via SAML Redirect Binding","url":"https://feed.craftedsignal.io/briefs/2026-09-keycloak-saml-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}