CVE-2026-7307
Red Hat Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.16, Red Hat build of Keycloak 26.4 취약점
A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.
- 대응 우선순위
- 점검
- CVSS
- 7.5
- EPSS
- 0.74% 백분위 50.5% · 2026.07.15 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.05.19