CVE-2026-4874
Published: Mar 26, 2026
Modified: Apr 1, 2026
CVSS v3.1
3.1
Description
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder. Successful exploitation allows the attacker to make HTTP requests from the Keycloak server’s network context, potentially probing internal networks or internal APIs, leading to information disclosure.
| Vendor | Product | Versions |
|---|---|---|
Red Hat | Red Hat Build of Keycloak | All versions |
Red Hat | Red Hat Build of Keycloak | All versions |
Red Hat | Red Hat Build of Keycloak | All versions |
Red Hat | Red Hat JBoss Enterprise Application Platform 8 | All versions |
Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | All versions |
Red Hat | Red Hat Single Sign-On 7 | All versions |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now