Skip to main content

Missing XML Validation in org.keycloak:keycloak-services

CVE-2026-1190

  • org.keycloak:keycloak-services
Severity Low
Score 3.1/10

Summary

A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationData`. This allows an attacker to delay the expiration of SAML responses, potentially extending the time a response is considered valid and leading to unexpected session durations or resource consumption.

  • HIGH
  • NETWORK
  • LOW
  • UNCHANGED
  • REQUIRED
  • NONE
  • NONE
  • NONE

CWE-112 - Missing XML Validation

The software accepts XML from an untrusted source but does not validate the XML against the proper schema.

Advisory Timeline

  • Published