CVE-2026-7307
Red Hat Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.16, Red Hat build of Keycloak 26.4
A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.
- CVSS
- 7.5
- EPSS
- 0.74% 50.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.19