CVE-2023-6291EPSS p59.9%
CVE-2023-6291CVE-2023-6291
redhat / keycloak
Description
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.
Scoring
| CVSS | 7.1 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
| EPSS | 0.95% probability of exploitation · percentile 59.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-22 |