|
411
|
- |
|
-
|
-
|
Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destination buffer.
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-6325
|
2026-06-26 20:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
412
|
- |
|
-
|
-
|
When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC.
New
|
CWE-757
Algorithm Downgrade
|
CVE-2026-6092
|
2026-06-26 20:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
413
|
- |
|
-
|
-
|
TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificate and CertificateVerify. The post-handshake-auth e…
New
|
CWE-287
Improper Authentication
|
CVE-2026-55962
|
2026-06-26 20:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
414
|
- |
|
-
|
-
|
Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A cached session could be resumed under a different SNI…
New
|
CWE-287
Improper Authentication
|
CVE-2026-11703
|
2026-06-26 20:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
415
|
- |
|
-
|
-
|
OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the target serial to be reported as the revocation status o…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-10098
|
2026-06-26 20:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
416
|
8.1 |
HIGH
Network
|
-
|
-
|
A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission ch…
New
|
CWE-1025
Comparison Using Wrong Factors
|
CVE-2026-9800
|
2026-06-26 17:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
417
|
4.6 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission reque…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-9799
|
2026-06-26 17:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
418
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client t…
New
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-9705
|
2026-06-26 17:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
419
|
7.7 |
HIGH
Network
|
-
|
-
|
A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to r…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-9099
|
2026-06-26 17:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
420
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoints, could bypass client Unif…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-9086
|
2026-06-26 17:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|