CVE-2026-7504 — keycloak
CVE-2026-7504 is a Open Redirect vulnerability in keycloak. A fix is available for keycloak — see the affected versions and patch details below.
Org.keycloak/keycloak-services: open redirect when using wildcard valid redirect uris in keycloak
Exploitation Status
No confirmed exploitation observed yet
- A successful exploit gives an attacker total control of the affected component, not partial access.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-7504.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Real-World Exposure
keycloakReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Bitnami packages — download data is not available via public APIs for these ecosystems.
Description
A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users to unauthorized URLs, potentially leading to the exposure of sensitive information within the domain or facilitating further attacks. This vulnerability specifically affects Keycloak clients configured with a wildcard (*) in the "Valid Redirect URIs" field and requires user interaction to be successfully exploited.
The issue stems from a discrepancy in how Keycloak and the underlying Java URI implementation handle the user-info component of a URL. If a malicious redirect URL is constructed using multiple @ characters in the user-info section, Java's URI parser fails to extract the user-info, leaving only the raw authority field. Consequently, Keycloak's validation check fails to detect the malformed user-info, falls back to a wildcard comparison, and incorrectly permits the malicious redirect.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦Bitnami | keycloak | ≥ 26.4.0&&< 26.4.12 | 26.4.12 |
Affected Products
build of keycloakredhatDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for keycloak, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update keycloak to 26.4.12 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-7504 is resolved across your whole dependency graph.
Workarounds
Stop reflecting attacker-controlled destinations: resolve every redirect target against an allowlist of paths or hosts you own, prefer a server-side key over a full URL in the request, and reject absolute URLs entirely where the flow only ever needs a relative one.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
This Moderate impact flaw in Keycloak allows for open redirection when a client is configured with a wildcard in its Valid Redirect URIs. An attacker could craft a malicious URL that, upon user interaction, bypasses validation and redirects to arbitrary locations within the domain, potentially leading to information…
To mitigate this vulnerability, Red Hat recommends avoiding the use of wildcard characters in the "Valid Redirect URIs" field for clients within Keycloak. Instead, explicitly list all allowed redirect URIs. Review all client configurations to ensure that wildcards are not used unless absolutely necessary, and if used, ensure that the client application is robust against open redirect vulnerabilities. Changes to client configurations in Keycloak may require a restart or reload of the Keycloak service to take effect, which could impact active user sessions.Source: Red Hat security advisory for CVE-2026-7504 (CC BY 4.0)
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat build of Keycloak 26.2 | rhbk/keycloak-operator-bundle:26.2.16-1 | RHSA-2026:19595 |
| Red Hat build of Keycloak 26.2.16 | rhbk/keycloak-rhel9-operator | RHSA-2026:19594 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-operator-bundle:26.4.12-1 | RHSA-2026:19597 |
| Red Hat build of Keycloak 26.4.12 | rhbk/keycloak-rhel9-operator | RHSA-2026:19596 |
Frequently Asked Questions
Is CVE-2026-7504 in your dependencies?
Find it across Bitnami, including transitive dependencies.