Sceawere

Vulnerability Detail

CVE-2026-105301UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Keycloak SSRF via X.509 CRL

Vulnerability Metadata

Severity
Medium
Score / CVSS
4
Creation Date
12h ago
Vendor
Red Hat
Product
Red Hat Build of Keycloak
Attack Type
Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management. The issue occurs when the server is configured to check certificate revocation using CRL Distribution Points or OCSP. An attacker can provide a specially crafted certificate that points to a malicious server, causing Keycloak to make unauthorized outbound requests to internal or external endpoints before the certificate is fully validated. This can lead to a blind server-side request forgery (SSRF) attack.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.0",
  "pubDate": "2026-10-05T06:16:58.207Z",
  "pubdate": "2026-10-05T06:16:58.207Z",
  "executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in the X.509 client-certificate authenticator component of Keycloak. This flaw is triggered when the server is configured to perform certificate revocation checks via CRL Distribution Points or OCSP.\nThe vulnerability allows an unauthenticated attacker to supply a specially crafted client certificate containing malicious Uniform Resource Identifiers (URIs). When the Keycloak server processes the certificate for revocation validation, it initiates outbound network requests to these attacker-controlled locations.\nThe primary risk involves the exploitation of the server's internal network position to perform blind SSRF attacks. By leveraging the server's identity to reach restricted internal services or external endpoints, an attacker can conduct port scanning, probe internal infrastructure, or potentially exfiltrate metadata.\nExploitation requires the server to have revocation checking enabled and relies on the server's ability to reach the malicious endpoints defined in the certificate's extensions. The impact is significant as it allows the bypass of perimeter security controls by utilizing the server as a proxy for malicious requests.",
  "technicalDetails": "The vulnerability originates within the X.509 client-certificate authentication logic in Keycloak. When certificate revocation checking is enabled, the server is instructed to parse the CRL Distribution Points (CDP) or OCSP responder addresses embedded within the X.509 certificate metadata.\nThe root cause is a failure to properly sanitize or validate the URLs provided within the certificate extensions before the underlying HTTP/TLS client attempts to resolve and fetch the revocation status. Because these fields are inherently untrusted input provided by the client, they act as vectors for instructing the server to initiate arbitrary outbound connections.\nThe attack flow begins when an attacker initiates an authentication handshake with the Keycloak server, presenting a malicious client certificate. This certificate includes crafted extensions pointing to a target URI of the attacker's choosing. Upon receipt of the certificate, the Keycloak authentication provider triggers the revocation check process. The server-side code proceeds to extract the CDP or OCSP URI and initiates an outbound request to that address to verify if the certificate has been revoked.\nSince this process occurs during the initial authentication phase, it facilitates blind SSRF. The attacker does not necessarily require valid credentials to reach the code path, provided the authentication flow allows for certificate processing before the identity is fully established. The server performs these requests with the network privileges of the Keycloak instance, effectively acting as an open proxy for the attacker.\nIn a blind SSRF scenario, the attacker cannot see the direct output of the request; however, they can observe timing differences, server responsiveness, or rely on internal infrastructure interaction to confirm successful exploitation. This behavior can be used to map internal services, circumvent firewall restrictions, or interact with cloud metadata services if the Keycloak instance is hosted in a cloud environment (e.g., AWS IMDS), leading to full environment compromise.\nThe vulnerability is restricted to environments where Keycloak is explicitly configured to perform revocation validation. If revocation checking is disabled, the specific code path responsible for parsing the malicious extensions is bypassed, rendering the system safe from this specific SSRF vector."
}
CVE-2026-105301: Keycloak SSRF via X.509 CRL (MEDIUM Severity, CVSS: 4.0) | Sceawere