Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. keycloak

keycloak

enriched
Identity & Access Management

keycloak.org ↗ · required email domain for this vendor's users

Do you work at keycloak?

This profile was built from public sources and hasn't been claimed yet. Claiming it lets you correct what's wrong and add details only you can confirm — and marks that information as vendor-verified for buyers.

Free, and it does not affect ranking, placement, or comparison results. The first person verified on keycloak's email domain becomes the profile admin.

Claim this profileAlready have an account?

Trust profileHow to read thisFive separate questions a buyer actually asks, each answered with its own evidence and a link to the source. There is deliberately no overall score: a single number invites comparison it cannot support, and would mostly reflect how much of keycloak we have managed to scan rather than anything about the vendor.

Not checked means we have not looked yet, and is never counted against a vendor. Limited means we did look, but found only one line of evidence — enough to report, not enough to corroborate.

checked 6 of 16 signals
  • Limited

    Independently verified

    Has anyone other than the vendor confirmed this?

    checked 3 of 4

    Nothing here has been confirmed by an independent third party yet.

    • No third-party certifications found
    • Profile not claimed by the vendor
  • Limited

    Operating durability

    Is this a real, durable business?

    checked 2 of 4

    How long this vendor has been operating, and who stands behind them.

    • Headquarters location not disclosed on their site
  • Mixed

    Behaviour under stress

    What do they do when something goes wrong?

    checked 1 of 3

    What their public record shows about handling vulnerabilities and outages.

    • 99 published CVE(s) — a public disclosure record exists
    • 8 rated critical
  • Not checked

    Disclosure posture

    Do they tell you the awkward things unprompted?

    checked 0 of 3

    We have not checked what this vendor discloses publicly yet.

    Nothing checked here yet — this is not a mark against keycloak.

  • Not checked

    Momentum

    Are they still shipping, or coasting?

    checked 0 of 2

    We have not tracked this vendor's release activity yet.

    Nothing checked here yet — this is not a mark against keycloak.

Data coverage: 10/100What this measures (and doesn't)

Not a quality rating or endorsement — a measure of how much verified, disclosed data we actually have about this vendor. A low score usually means "we don't have much verified information yet," not "this is a bad vendor." Never used to sort or rank vendor lists.

Verification depth0/100
Security signal0/100
Buyer feedbackno data yet (0 reviews so far)
Profile completeness0/100
claim · HQ · materials · screenshots · integrations · certifications · security check

The platform admin controls the formula's weights.

Data coverage profileHow to read thisThe same four components behind the data coverage score above, shaped instead of listed — a vendor strong on verification but thin on buyer feedback looks visibly different from one that's the other way around. Security and feedback plot at the neutral midpoint (50) when there's no data yet (no products tracked, no reviews), matching how the actual score itself treats missing data — not a guess either way.

VerificationSecurityFeedbackCompletenessThis vendor — Verification: 0This vendor — Security: 0This vendor — Feedback: no data yetThis vendor — Completeness: 0

Buyer reviewsUI-14 — verified-buyer reviewsWritten only by domain-verified buyers at other companies, attributed to their company domain (never their identity), and moderated. Buyer-sourced opinion, clearly separate from the neutral catalog facts above — and never an input to search or comparison ordering.

verified buyers only

No buyer reviews yet.

Reputation ratingUI-20 — anonymous ratingA single anonymous 5-star signal from buyers, resellers, and analysts who've engaged with this vendor — separate from the domain-attributed reviews above. No rater identity is ever shown, not even at company level.

anonymous

No ratings in this window yet.

Open-source IAM solution for SSO, MFA, and identity federation AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →

CVE severity over timeUI-24 — CVE severity timelineEvery known CVE with a disclosure date and severity, plotted by when it was published — lets you see whether disclosures are trending toward more or less severe, not just a raw count. Same NVD-sourced, name-matched data as the list below.

LOWMEDIUMHIGHCRITICAL201820192020202120222023CVE-2023-6563 · HIGH 7.7 · 2023-12-14CVE-2023-2422 · MEDIUM 5.5 · 2023-10-04CVE-2022-4137 · HIGH 8.1 · 2023-09-26CVE-2022-3916 · MEDIUM 6.8 · 2023-09-20CVE-2022-1438 · MEDIUM 6.4 · 2023-09-20CVE-2023-4918 · HIGH 8.8 · 2023-09-13CVE-2022-4361 · CRITICAL 10.0 · 2023-07-08CVE-2023-1664 · MEDIUM 6.5 · 2023-05-26CVE-2023-1477 · HIGH 7.2 · 2023-04-28CVE-2022-1274 · MEDIUM 5.4 · 2023-03-30CVE-2022-2237 · MEDIUM 6.1 · 2023-03-28CVE-2023-24457 · MEDIUM 6.5 · 2023-01-27CVE-2023-24456 · CRITICAL 9.8 · 2023-01-27CVE-2023-0105 · MEDIUM 6.5 · 2023-01-13CVE-2023-0091 · LOW 3.8 · 2023-01-13CVE-2022-3782 · CRITICAL 9.1 · 2023-01-13CVE-2023-22492 · MEDIUM 5.9 · 2023-01-12CVE-2022-2256 · LOW 3.8 · 2022-09-02CVE-2022-36051 · HIGH 8.7 · 2022-09-01CVE-2022-0225 · MEDIUM 5.4 · 2022-08-26CVE-2021-3754 · MEDIUM 5.3 · 2022-08-26CVE-2021-3632 · HIGH 7.5 · 2022-08-26CVE-2021-3827 · MEDIUM 6.8 · 2022-08-23CVE-2020-35509 · MEDIUM 5.4 · 2022-08-23CVE-2021-3513 · HIGH 7.5 · 2022-08-22CVE-2022-2668 · HIGH 7.2 · 2022-08-05CVE-2022-1245 · CRITICAL 9.8 · 2022-07-08CVE-2021-3461 · HIGH 7.1 · 2022-04-02CVE-2021-20323 · MEDIUM 6.1 · 2022-03-25CVE-2022-27225 · MEDIUM 6.5 · 2022-03-16CVE-2021-4133 · HIGH 8.8 · 2022-01-26CVE-2021-3637 · HIGH 7.5 · 2021-07-09CVE-2021-3424 · MEDIUM 5.3 · 2021-06-01CVE-2021-20195 · CRITICAL 9.6 · 2021-05-28CVE-2020-27826 · MEDIUM 4.2 · 2021-05-28CVE-2021-20202 · HIGH 7.3 · 2021-05-12CVE-2021-20222 · HIGH 7.5 · 2021-03-23CVE-2021-3141 · HIGH 7.8 · 2021-03-18CVE-2021-20262 · MEDIUM 6.8 · 2021-03-09CVE-2020-27838 · MEDIUM 6.5 · 2021-03-09CVE-2020-14359 · HIGH 7.3 · 2021-02-23CVE-2020-1717 · LOW 2.7 · 2021-02-11CVE-2020-10734 · LOW 3.3 · 2021-02-11CVE-2020-1725 · MEDIUM 5.4 · 2021-01-29CVE-2020-1723 · MEDIUM 6.1 · 2021-01-29CVE-2020-14302 · MEDIUM 4.9 · 2020-12-16CVE-2020-10770 · MEDIUM 5.3 · 2020-12-16CVE-2020-14389 · HIGH 8.1 · 2020-11-17CVE-2020-10776 · MEDIUM 4.8 · 2020-11-17CVE-2020-14366 · MEDIUM 6.8 · 2020-11-09CVE-2020-1694 · MEDIUM 4.9 · 2020-09-16CVE-2020-10748 · MEDIUM 6.1 · 2020-09-16CVE-2020-10758 · HIGH 7.5 · 2020-09-16CVE-2020-1727 · MEDIUM 6.4 · 2020-06-22CVE-2020-1758 · MEDIUM 5.3 · 2020-05-15CVE-2020-1714 · HIGH 8.8 · 2020-05-13CVE-2020-1718 · HIGH 7.1 · 2020-05-13CVE-2020-1724 · MEDIUM 4.3 · 2020-05-12CVE-2020-1698 · MEDIUM 5.0 · 2020-05-11CVE-2019-10170 · MEDIUM 6.6 · 2020-05-08CVE-2019-10169 · MEDIUM 6.6 · 2020-05-08CVE-2020-10686 · MEDIUM 4.1 · 2020-05-05CVE-2020-1728 · MEDIUM 4.8 · 2020-04-06CVE-2020-1744 · MEDIUM 5.6 · 2020-03-24CVE-2020-1731 · CRITICAL 9.1 · 2020-03-02CVE-2020-1697 · MEDIUM 6.1 · 2020-02-10CVE-2019-14820 · MEDIUM 4.3 · 2020-01-08CVE-2014-3652 · MEDIUM 6.1 · 2019-12-16CVE-2014-3656 · MEDIUM 6.1 · 2019-12-10CVE-2019-14910 · CRITICAL 9.8 · 2019-12-05CVE-2019-14909 · HIGH 8.3 · 2019-12-04CVE-2014-3655 · MEDIUM 4.3 · 2019-11-13CVE-2019-14832 · HIGH 7.5 · 2019-10-15CVE-2019-10201 · HIGH 8.1 · 2019-08-14CVE-2019-10199 · HIGH 8.8 · 2019-08-14CVE-2019-3875 · MEDIUM 6.5 · 2019-06-12CVE-2019-10157 · MEDIUM 4.7 · 2019-06-12CVE-2019-3868 · LOW 3.8 · 2019-04-24CVE-2018-14637 · MEDIUM 6.1 · 2018-11-30CVE-2018-14658 · MEDIUM 6.1 · 2018-11-14CVE-2018-14657 · HIGH 8.1 · 2018-11-14CVE-2018-14655 · MEDIUM 4.6 · 2018-11-14CVE-2018-10894 · MEDIUM 5.4 · 2018-08-01CVE-2016-8609 · LOW 3.7 · 2018-08-01CVE-2017-2646 · HIGH 7.5 · 2018-07-27CVE-2017-2582 · MEDIUM 6.5 · 2018-07-26CVE-2018-10912 · MEDIUM 4.9 · 2018-07-24CVE-2017-2585 · MEDIUM 5.9 · 2018-03-12CVE-2016-8629 · MEDIUM 6.5 · 2018-03-12CVE-2017-12161 · HIGH 8.8 · 2018-02-21CVE-2017-15112 · HIGH 7.8 · 2018-01-20CVE-2017-15111 · MEDIUM 5.5 · 2018-01-20CVE-2014-3651 · HIGH 7.5 · 2017-12-29CVE-2017-12160 · HIGH 7.2 · 2017-10-26CVE-2017-12159 · HIGH 7.5 · 2017-10-26CVE-2017-12158 · MEDIUM 5.4 · 2017-10-26CVE-2014-3709 · HIGH 8.8 · 2017-10-18CVE-2017-7474 · CRITICAL 9.8 · 2017-05-12

Known CVEs (99)About this listSourced from the public NVD database, matched by vendor name. This is a name-based match, not exact version tracking — always check the linked NVD record for affected versions before drawing conclusions. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2023-6563 ↗HIGH 7.72023

    An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 sav…

  • CVE-2023-2422 ↗MEDIUM 5.52023

    A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a prop…

  • CVE-2022-4137 ↗HIGH 8.12023

    A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Key…

  • CVE-2022-3916 ↗MEDIUM 6.82023

    A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and …

  • CVE-2022-1438 ↗MEDIUM 6.42023

    A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability.

  • CVE-2023-4918 ↗HIGH 8.82023

    A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "password" and "password-confirm" field from the form …

  • CVE-2022-4361 ↗CRITICAL 10.02023

    Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malic…

  • CVE-2023-1664 ↗MEDIUM 6.52023

    A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Us…

  • CVE-2023-1477 ↗HIGH 7.22023

    Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authenticator Extension: before 7.10.2, before 8.0.3.

  • CVE-2022-1274 ↗MEDIUM 5.42023

    A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other a…

  • CVE-2022-2237 ↗MEDIUM 6.12023

    A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso function.

  • CVE-2023-24457 ↗MEDIUM 6.52023

    A cross-site request forgery (CSRF) vulnerability in Jenkins Keycloak Authentication Plugin 2.3.0 and earlier allows attackers to trick users into logging in to the attacker's account.

  • CVE-2023-24456 ↗CRITICAL 9.82023

    Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login.

  • CVE-2023-0105 ↗MEDIUM 6.52023

    A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker can shadow other users with the same email and lock…

  • CVE-2023-0091 ↗LOW 3.82023

    A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitiv…

  • CVE-2022-3782 ↗CRITICAL 9.12023

    keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious …

  • CVE-2023-22492 ↗MEDIUM 5.92023

    ZITADEL is a combination of Auth0 and Keycloak. RefreshTokens is an OAuth 2.0 feature that allows applications to retrieve new access tokens and refresh the user's session without the need for interac…

  • CVE-2022-1970 ↗2022

    Rejected reason: The originally reported issue in https://github.com/syedsohaibkarim/OpenRedirect-Keycloak18.0.0 is a known misconfiguration, and recommendation already exists in the Keycloak document…

  • CVE-2022-2256 ↗LOW 3.82022

    A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console…

  • CVE-2022-36051 ↗HIGH 8.72022

    ZITADEL combines the ease of Auth0 and the versatility of Keycloak.**Actions**, introduced in ZITADEL **1.42.0** on the API and **1.56.0** for Console, is a feature, where users with role.`ORG_OWNER` …

  • …and 79 more

Competitors (12)

full alternatives comparison →
1PasswordAbbey LabsAceissAirrivedAkeyless SecurityAlcorAlibaba CloudAndromeda SecurityAponoAqueraARCONArexdata

Products (1)

Identity & Access Management

1
  • KeycloakAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Open-source IAM solution for SSO, MFA, and identity federation