Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
To mitigate this vulnerability, ensure that Keycloak's LDAP user-storage providers are configured to connect only to trusted and secure LDAP servers. Avoid configuring LDAP federation with unverified or potentially malicious LDAP endpoints. Additionally, always use TLS for LDAP connections to prevent Man-in-the-Middle attacks. If an upstream LDAP server is compromised, it should be isolated and secured immediately.
Thu, 28 May 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat build Of Keycloak
|
|
| Vendors & Products |
Redhat build Of Keycloak
|
Thu, 28 May 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could exploit this vulnerability. By sending a malformed LDAP password policy response during a password authentication request, the attacker can trigger an OutOfMemoryError. This causes the Keycloak Java Virtual Machine (JVM) to terminate, leading to a denial of service (DoS) for all realms on the affected node. | |
| Title | Keycloak: keycloak: denial of service via malformed ldap password policy response | |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| Weaknesses | CWE-1284 | |
| CPEs | cpe:/a:redhat:build_keycloak: | |
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-05-28T04:42:10.331Z
Reserved: 2026-05-28T04:00:46.722Z
Link: CVE-2026-9801
No data.
Status : Received
Published: 2026-05-28T06:16:29.493
Modified: 2026-05-28T06:16:29.493
Link: CVE-2026-9801
No data.
OpenCVE Enrichment
Updated: 2026-05-28T09:30:05Z