Improper Validation of Syntactic Correctness of Input Affecting org.keycloak:keycloak-saml-core package, versions [,26.6.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.74% (51st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGKEYCLOAK-16873870
  • published24 May 2026
  • disclosed19 May 2026
  • creditUnknown

Introduced: 19 May 2026

CVE-2026-7307  (opens in a new tab)
CWE-1286  (opens in a new tab)

How to fix?

Upgrade org.keycloak:keycloak-saml-core to version 26.6.2 or higher.

Overview

org.keycloak:keycloak-saml-core is an Identity and Access Management plugin for Keycloak.

Affected versions of this package are vulnerable to Improper Validation of Syntactic Correctness of Input in the SAMLParser and SAML11ParserUtil code paths that handle SAML 1.1 assertions and protocol requests. An attacker can trigger a ParsingException and disrupt SAML request processing by supplying malformed SAML 1.1 XML, including unexpected text or invalid event sequences inside Assertion, AttributeQuery, AuthenticationQuery, or AuthorizationDecisionQuery elements.

Note: While the fix was back-ported to version 26.4.12, this version has not been published to Maven Central

CVSS Base Scores

version 4.0
version 3.1