CWE-112: Missing XML Validation
The product accepts XML from an untrusted source but does not validate the XML against the proper schema.
7 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-1190 — Org.keycloak/keycloak-services: keycloak saml brokering: response delay due to unchecked notonorafter in subjectconfirmationdata
Recently published
- CVE-2026-1190 — Org.keycloak/keycloak-services: keycloak saml brokering: response delay due to unchecked notonorafter in subjectconfirmationdata