Keycloak Generates an Error Message Containing Sensitive Information
Moderate severity
GitHub Reviewed
Published
May 28, 2026
to the GitHub Advisory Database
•
Updated Jul 1, 2026
Package
Affected versions
<= 26.4.7
>= 26.5.0, < 26.6.3
Patched versions
26.6.3
Description
Published by the National Vulnerability Database
May 28, 2026
Published to the GitHub Advisory Database
May 28, 2026
Last updated
Jul 1, 2026
Reviewed
Jul 1, 2026
A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client's protocol type, leading to information disclosure.
References