CVE-2026-4874
Last modified
CVE-2026-4874 is a low-severity vulnerability rated 3.1/10 on the CVSS scale. A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder. Successful exploitation allows the attacker to make HTTP requests from the Keycloak server’s network context, potentially probing internal networks or internal APIs, leading to information disclosure.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Build Of Keycloak | All versions |
| Redhat | Jboss Enterprise Application Platform | 8.0.0 |
| Redhat | Jboss Enterprise Application Platform Expansion Pack | All versions |
| Redhat | Single Sign-On | 7.0 |
References
- https://access.redhat.com/security/cve/CVE-2026-4874Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2451611Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-4874?
How severe is CVE-2026-4874?
How do I fix CVE-2026-4874?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-48732Warp is an agentic development environment. From 0.2023.03.2…8.8
- CVE-2026-48733ImageMagick is free and open-source software used for editin…4.7
- CVE-2026-48734ImageMagick is free and open-source software used for editin…5.5
- CVE-2026-48735pypdf is a free and open-source pure-python PDF library. Pri…5.5
- CVE-2026-48736Symfony is a PHP framework for web and console applications …8.6
- CVE-2026-48737pyLoad is a free and open-source download manager written in…4.9
- CVE-2026-48743Envoy is an open source edge and service proxy designed for …7.5
- CVE-2026-48744Saleor is an e-commerce platform. From 3.14.67 until 3.21.67…6.5
- CVE-2026-48745Traccar Client is a GPS tracking mobile app for sending loca…9.3
- CVE-2026-48746vLLM is an inference and serving engine for large language m…9.1
- CVE-2026-48747Symfony is a PHP framework for web and console applications …5.3
- CVE-2026-48748Netty is a network application framework for development of …7.5
Are you affected by CVE-2026-4874?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
