Nixpkgs security tracker

Try the new UI
Login with GitHub

Details of issue NIXPKGS-2026-2645

NIXPKGS-2026-2645
published 4 days, 10 hours ago
Keycloak: Replay protection bypass leads to unauthorized access via database driver semantics mismatch
Permalink CVE-2026-90997
7.4 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 4 days, 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    17 packages
    • keycloak-config-cli
    • terraform-providers.keycloak
    • keycloakPlugins.keycloak-orgs
    • keycloakPlugins.keycloak-discord
    • python313Packages.python-keycloak
    • python314Packages.python-keycloak
    • keycloakPlugins.keycloak-magic-link
    • terraform-providers.keycloak_keycloak
    • keycloakPlugins.keycloak-home-idp-discovery
    • keycloakPlugins.keycloak-restrict-client-auth
    • keycloakPlugins.keycloak-2fa-app-authenticator
    • keycloakPlugins.keycloak-2fa-sms-authenticator
    • keycloakPlugins.keycloak-secrets-vault-provider
    • keycloakPlugins.apple-identity-provider-keycloak
    • keycloakPlugins.keycloak-2fa-email-authenticator
    • keycloakPlugins.keycloak-enforce-mfa-authenticator
    • keycloakPlugins.keycloak-remember-me-authenticator
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Keycloak: Replay protection bypass leads to unauthorized access via database driver semantics mismatch

A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vulnerability enables an attacker who intercepts single-use security artifacts, such as JWT client assertions, DPoP proofs, or one-time password (TOTP) codes, to replay them. Successful exploitation grants unauthorized access to the token endpoint or login flow.

Affected products

keycloak-services
  • <26.7.4

Matching in nixpkgs

pkgs.keycloak

Identity and access management for modern applications and services

Ignored packages (17)

Package maintainers

Needs something for stable.