← All Advisories

CVE-2026-7307

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-7307

Key Details

CVECVE-2026-7307
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-10-06
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsRed Hat Build of Keycloak, Red Hat RHEL-8 based Middleware Containers, Red Hat build of Keycloak 26.2, and Red Hat build of Keycloak 26.4
Classified asCWE-1286 (Improper Validation of Syntactic Correctness of Input)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Build of Keycloak
Red HatRHEL-8 based Middleware Containers
Red HatRed Hat build of Keycloak 26.2
Red HatRed Hat build of Keycloak 26.4
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-7307
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-7307
Vendor advisoryhttps://access.redhat.com/errata/RHSA-2026:19594