CVE-2026-9801Redhat · Build_of_keycloak
Vulnerability data via NVD (ingested)
A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could exploit this vulnerability. By sending a malformed LDAP password policy response during a password authentication request, the attacker can trigger an OutOfMemoryError. This causes the Keycloak Java Virtual Machine (JVM) to terminate, leading to a denial of service (DoS) for all realms on the affected node.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-9801product:"Redhat Build Of Keycloak"http.html:"Build Of Keycloak"More intel sources (5)
vuln:CVE-2026-9801vulnerabilities.cve_id: CVE-2026-9801CVE-2026-9801CVE-2026-9801"CVE-2026-9801" exploit -site:nvd.nist.gov