Intel

AIKIDO-2026-10305

keycloak-services is vulnerable to Missing XML Validation

Missing XML ValidationCVE-2026-1190 Published Mar 9, 2026

31

Low Risk

This Affects:

javakeycloak-services
0.0.1 - 26.5.3
Fixed in 26.5.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to improper validation of SAML assertions. When configured as a client in a Security Assertion Markup Language (SAML) setup, the application does not validate the NotOnOrAfter timestamp within the SubjectConfirmationData element. This allows an attacker to reuse or delay the expiration of SAML responses, potentially extending the period during which a response is considered valid and leading to unintended session durations or resource consumption.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

keycloak-services is vulnerable to Missing XML Validation in versions 0.0.1 - 26.5.3.

How to fix this

Upgrade the org.keycloak:keycloak-services library to a patch version.