Security Advisory

CVE-2026-1518

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-02-02 07:17:46
Last updated 2026-07-24 14:07:33
Assigner redhat
CVSS score not scored
State REJECTED

Description

DO NOT USE THIS CANDIDATE NUMBER. After further review by the Keycloak project and Red Hat, the reported SSRF via client registration/backchannel notification URIs was determined not to constitute a security vulnerability. The reported behavior is expected administrator-controlled functionality, and Keycloak provides documented mitigations through Client Policies, including the Secure Client URIs Pattern executor. Therefore, this CVE has been rejected.