HIGH 7.5 NVD
CVE-2026-79651
A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and them
A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitrary locale tags from unauthenticated requests and stores them in a permanent in-memory cache without limits. An attacker can exploit this by sending a large number of unique locale tags, eventually causing the server to run out of memory and crash.
References
- https://access.redhat.com/errata/RHSA-2026:68276
- https://access.redhat.com/errata/RHSA-2026:68277
- https://access.redhat.com/errata/RHSA-2026:68278
- https://access.redhat.com/errata/RHSA-2026:68280
- https://access.redhat.com/security/cve/CVE-2026-79651
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-09-16 via NVD.
vulnfeed aggregates 14391 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.