CVE-2026-18212
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zlib memory after use. An unauthenticated attacker can exploit this by sending repeated malformed SAML requests, leading to native memory exhaustion and a denial of service.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.16-2 < * | unaffected |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-26 < * | unaffected |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-26 < * | unaffected |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6.7-3 < * | unaffected |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-20 < * | unaffected |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-20 < * | unaffected |
Weaknesses
- CWE-401: Missing Release of Memory after Effective Lifetime
Workarounds
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
- https://access.redhat.com/errata/RHSA-2026:68276
- https://access.redhat.com/errata/RHSA-2026:68277
- https://access.redhat.com/errata/RHSA-2026:68278
- https://access.redhat.com/errata/RHSA-2026:68280
- https://access.redhat.com/security/cve/CVE-2026-18212
- https://bugzilla.redhat.com/show_bug.cgi?id=2508307
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.