Sceawere

Vulnerability Detail

CVE-2026-103884UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Keycloak Path Traversal CRL Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
Red Hat
Product
Red Hat Build of Keycloak
Attack Type
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
Attack Complexity
HIGH

Narrative and Response

Description

A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-01T18:17:12.683Z",
  "pubdate": "2026-10-01T18:17:12.683Z",
  "executiveSummary": "A critical path traversal and resource exhaustion vulnerability exists in the X.509 client certificate authenticator within Keycloak.\nThe flaw manifests when the Certificate Revocation List (CRL) Distribution Point checking feature is enabled, allowing an attacker to supply a malicious client certificate containing manipulated file paths.\nThis vulnerability permits an attacker to perform unauthorized file system reads, potentially leading to sensitive information disclosure, or to induce a system crash via memory exhaustion through the forced loading of excessively large files.\nThe affected component is the X.509 client certificate authentication logic, which fails to sanitize user-provided inputs used in CRL processing.\nSuccessful exploitation requires the attacker to submit a specially crafted X.509 certificate to the authentication endpoint, which may be reachable remotely depending on the Keycloak deployment configuration.\nThe risk is significant as it provides a vector for local file inclusion (LFI) and Denial of Service (DoS), potentially compromising the confidentiality and availability of the underlying Keycloak host.",
  "technicalDetails": "The vulnerability resides in the X.509 certificate authentication provider component responsible for verifying client certificates against Certificate Revocation Lists (CRL). When CRL Distribution Point (CDP) checking is enabled, Keycloak parses the certificate extension to identify the URI or file path from which the revocation list should be retrieved.\nThe root cause is an improper validation of the path provided within the X.509 certificate's CDP extension. The application fails to implement adequate input sanitization or path restriction policies when resolving these locations, allowing for directory traversal patterns.\nThe attack flow commences when an attacker presents a specially crafted X.509 client certificate during the TLS handshake or authentication flow. By embedding crafted path traversal sequences (e.g., '../') or absolute local file system paths within the CDP extension, the attacker forces the Keycloak server process to interact with resources outside the intended directory scope.\nWhen the server attempts to process the certificate, the underlying file handling mechanism interprets these malicious paths, leading to two primary exploitation vectors:\nFirst, Information Disclosure: If the system has sufficient read permissions, the server may read contents from arbitrary files on the local filesystem, which could subsequently be reflected in error messages, logs, or processed as revocation data, potentially exposing sensitive configuration files, credentials, or system artifacts.\nSecond, Denial of Service (DoS): The attacker can point the CRL retrieval process to large files or devices (such as /dev/zero or large system logs), causing the application to attempt to load these contents into memory. Because the system lacks a bound on the size of the file being read during the validation process, this leads to rapid heap exhaustion, resulting in an OutOfMemoryError and subsequent service crash.\nThis flaw is particularly dangerous because the certificate validation occurs early in the authentication pipeline, potentially before the user is fully authenticated. The attack surface is defined by the exposure of the Keycloak authentication endpoint to untrusted clients. By failing to validate the schema or the destination of the CRL location, the application essentially grants an attacker control over the file input path used by the JVM process running the Keycloak service."
}
CVE-2026-103884: Keycloak Path Traversal CRL Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere