
CVE-2026-4874 A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refres… https://www.cve.org/CVERecord?id=CVE-2026-4874
Post summary
Keycloak is vulnerable to an authenticated SSRF via manipulation of the client_session_host parameter, as reported in CVE-2026-4874; no PoC, exploit, or patch is mentioned.
