CVE-2026-1190
A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationData`. This allows an attacker to delay the expiration of SAML responses, potentially extending the time a response is considered valid and leading to unexpected session durations or resource consumption.
Scoring
- Severity
- LOW
- CVSS base score
- 3.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS probability
- 0.38%
- CWE
- CWE-112
- Published
- 2026-01-26
- Last modified
- 2026-03-12
Affected products
- Red Hat Red Hat build of Keycloak 26.4
- Red Hat Red Hat build of Keycloak 26.4
Weakness type
Related vulnerabilities
- CVE-2023-40310 — Missing XML Validation vulnerability in SAP PowerDesigner Client BPMN2 import
- CVE-2021-27780 — HCL BigFix Mobile / Modern Client Management is vulnerable to unauthenticated XML interaction
- CVE-2022-28213 — When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform -...
- CVE-2021-1359 — Cisco Web Security Appliance Privilege Escalation Vulnerability
- CVE-2020-27282 — In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in...
- CVE-2020-1975 — Missing XML Validation in PAN-OS Web Interface