CVE-2026-1518

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. After further review by the Keycloak project and Red Hat, the reported SSRF via client registration/backchannel notification URIs was determined not to constitute a security vulnerability. The reported behavior is expected administrator-controlled functionality, and Keycloak provides documented mitigations through Client Policies, including the Secure Client URIs Pattern executor. Therefore, this CVE has been rejected.
CVSS

No CVSS.

References

No reference.

Configurations

No configuration.

History

24 Jul 2026, 15:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 2.7
v2 : unknown
v3 : unknown
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2026-1518', 'source': 'secalert@redhat.com'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=2433727', 'source': 'secalert@redhat.com'}
CWE CWE-918
Summary
  • (es) Se encontró un fallo en la característica CIBA de Keycloak donde una validación insuficiente de los puntos finales de notificación de canal de retorno configurados por el cliente podría permitir solicitudes ciegas del lado del servidor a servicios internos.
Summary (en) A flaw was found in Keycloak’s CIBA feature where insufficient validation of client-configured backchannel notification endpoints could allow blind server-side requests to internal services. (en) Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. After further review by the Keycloak project and Red Hat, the reported SSRF via client registration/backchannel notification URIs was determined not to constitute a security vulnerability. The reported behavior is expected administrator-controlled functionality, and Keycloak provides documented mitigations through Client Policies, including the Secure Client URIs Pattern executor. Therefore, this CVE has been rejected.

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Se encontró un fallo en la característica CIBA de Keycloak donde una validación insuficiente de los puntos finales de notificación de canal de retorno configurados por el cliente podría permitir solicitudes ciegas del lado del servidor a servicios internos.

02 Feb 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-02 08:16

Updated : 2026-07-24 15:17


NVD link : CVE-2026-1518

Mitre link : CVE-2026-1518

CVE.ORG link : CVE-2026-1518


JSON object : View

Products Affected

No product.

CWE

No CWE.