A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.
rhbk/keycloak Red Hat / RHEL
Fixed in: rhel9@sha256:81773a34d38a8df4b07344fe4ba5670d18684b3579c9d2cf8d0690bf5ec5ab40_amd64 RHSA-2026:19597 Fixed in: operator-bundle@sha256:15286c44c4003e787b0bdf9a0bbc5083a2f2312eaf29ccd0c6943232ff52d729_amd64 RHSA-2026:19597 Fixed in: rhel9-operator@sha256:2a81955051fb0975bfcb77d25ed64c84038d3c7293f910aeb88f9241be531f9d_amd64 RHSA-2026:19597 Fixed in: rhel9@sha256:554cd90241225b6d64d0e7ada9a8ab50ae2054efdb2f5b2cbdb721475ea296df_arm64 RHSA-2026:19597 Fixed in: rhel9-operator@sha256:f80c9568ff4b3cc086b7107c8e68db5f548c2b51a01dd8c79d0c9705574a180c_arm64 RHSA-2026:19597 Fixed in: rhel9@sha256:68b61a98fcdfd46a166cabe097d609d65fd51181860f9ec7f691bbe5d2a986db_s390x RHSA-2026:19597 Fixed in: rhel9-operator@sha256:d915c75947df63aed99031401dbf570181dba3c5a484eb88438a27892eb7aa72_s390x RHSA-2026:19597 Fixed in: rhel9@sha256:fa7342d82f080bfe8ffaaf5ba204b98dc435897a388b1501d23a1541fe7f1272_ppc64le RHSA-2026:19597 Fixed in: rhel9-operator@sha256:d8185614aa82117680351c710a5d7b80703a9d450dd02a7becfd1405cbc5ecd5_ppc64le RHSA-2026:19597 Fixed in: rhel9@sha256:a9aeb0bc33a3461fe2d407896422719b21b184717956cbcebac0da976a220c1c_arm64 RHSA-2026:19595 Fixed in: rhel9-operator@sha256:88672078ac0b5a0da5b72c11751fa7b0c1c57679ec0f68cb1fe9ba76932397b5_arm64 RHSA-2026:19595 Fixed in: rhel9@sha256:58e692074e695bee04981aff9641db8070ba1a49ee6134fcc008046cd84da21d_ppc64le RHSA-2026:19595 Fixed in: rhel9-operator@sha256:13d8216c9f47a6f73ea6ea5c9ae7b8b38a89c3822e48eeed7271e50970132175_ppc64le RHSA-2026:19595 Fixed in: rhel9@sha256:7861ca2441bed95aab1ad43f9159d5c60b522fe3f43833f1847bd1d3ddef94d3_amd64 RHSA-2026:19595 Fixed in: operator-bundle@sha256:43a89aece29c0a33128e5a7be4ef26d96956fa125df89e22b183c40e50bb8a1d_amd64 RHSA-2026:19595 Fixed in: rhel9-operator@sha256:4d2cc26a505eda68f7270c8e8a02d794588f9c7ceec98b763d83e3875f957132_amd64 RHSA-2026:19595 Fixed in: rhel9@sha256:01a56463ad6790cf448e66f59a81c229db4159f42e563a13d19de051ec85ca86_s390x RHSA-2026:19595 Fixed in: rhel9-operator@sha256:fa9cebe14d003ae002137462fc5833e5634fd040d8f25a66230da9a753891914_s390x RHSA-2026:19595 rhbk/keycloak Rocky
Fixed in: rhel9@sha256:81773a34d38a8df4b07344fe4ba5670d18684b3579c9d2cf8d0690bf5ec5ab40_amd64 RHSA-2026:19597 Fixed in: operator-bundle@sha256:15286c44c4003e787b0bdf9a0bbc5083a2f2312eaf29ccd0c6943232ff52d729_amd64 RHSA-2026:19597 Fixed in: rhel9-operator@sha256:2a81955051fb0975bfcb77d25ed64c84038d3c7293f910aeb88f9241be531f9d_amd64 RHSA-2026:19597 Fixed in: rhel9@sha256:554cd90241225b6d64d0e7ada9a8ab50ae2054efdb2f5b2cbdb721475ea296df_arm64 RHSA-2026:19597 Fixed in: rhel9-operator@sha256:f80c9568ff4b3cc086b7107c8e68db5f548c2b51a01dd8c79d0c9705574a180c_arm64 RHSA-2026:19597 Fixed in: rhel9@sha256:68b61a98fcdfd46a166cabe097d609d65fd51181860f9ec7f691bbe5d2a986db_s390x RHSA-2026:19597 Fixed in: rhel9-operator@sha256:d915c75947df63aed99031401dbf570181dba3c5a484eb88438a27892eb7aa72_s390x RHSA-2026:19597 Fixed in: rhel9@sha256:fa7342d82f080bfe8ffaaf5ba204b98dc435897a388b1501d23a1541fe7f1272_ppc64le RHSA-2026:19597 Fixed in: rhel9-operator@sha256:d8185614aa82117680351c710a5d7b80703a9d450dd02a7becfd1405cbc5ecd5_ppc64le RHSA-2026:19597 Fixed in: rhel9@sha256:a9aeb0bc33a3461fe2d407896422719b21b184717956cbcebac0da976a220c1c_arm64 RHSA-2026:19595 Fixed in: rhel9-operator@sha256:88672078ac0b5a0da5b72c11751fa7b0c1c57679ec0f68cb1fe9ba76932397b5_arm64 RHSA-2026:19595 Fixed in: rhel9@sha256:58e692074e695bee04981aff9641db8070ba1a49ee6134fcc008046cd84da21d_ppc64le RHSA-2026:19595 Fixed in: rhel9-operator@sha256:13d8216c9f47a6f73ea6ea5c9ae7b8b38a89c3822e48eeed7271e50970132175_ppc64le RHSA-2026:19595 Fixed in: rhel9@sha256:7861ca2441bed95aab1ad43f9159d5c60b522fe3f43833f1847bd1d3ddef94d3_amd64 RHSA-2026:19595 Fixed in: operator-bundle@sha256:43a89aece29c0a33128e5a7be4ef26d96956fa125df89e22b183c40e50bb8a1d_amd64 RHSA-2026:19595 Fixed in: rhel9-operator@sha256:4d2cc26a505eda68f7270c8e8a02d794588f9c7ceec98b763d83e3875f957132_amd64 RHSA-2026:19595 Fixed in: rhel9@sha256:01a56463ad6790cf448e66f59a81c229db4159f42e563a13d19de051ec85ca86_s390x RHSA-2026:19595 Fixed in: rhel9-operator@sha256:fa9cebe14d003ae002137462fc5833e5634fd040d8f25a66230da9a753891914_s390x RHSA-2026:19595 TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works
Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.
Exploitability
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Impact
Confidentiality None
Integrity None
Availability High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
0.74% probability of exploitation in 30 days
51st percentile
Moderate risk: more likely to be exploited than 51% of all known CVEs.
Other CWE-1286 vulnerabilities, ordered by exploit likelihood. View all
Embed a live status badge for CVE-2026-7307 Markdown
[](https://tridentstack.com/cve/CVE-2026-7307)HTML
<a href="https://tridentstack.com/cve/CVE-2026-7307"><img src="https://tridentstack.com/cve/badge/CVE-2026-7307.svg" alt="CVE-2026-7307"></a>Find and fix vulnerabilities across your fleet TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-07-15.