GHSA-f6r7-6w34-x2gp
MODERATECVE-2026-9801A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could exploit this vulnerability. By sending a malformed LDAP password policy response during a password authentication request, the attacker can trigger an OutOfMemoryErr
- Affected
- < 26.6.3
- Fixed in
- 26.6.3
- Weakness
- CWE-1284
- Published
- 2026-05-28
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference