← Vulnerability feed

Vulnerability record · CVE-2020-10770 · published 15 December 2020

CVE-2020-10770: Keycloak OIDC request_uri parameter enables server-side request forgery

Redhat · Keycloak

Keycloak before 13.0.0 allows the OIDC request_uri parameter to force the server to fetch an unverified URL, resulting in a server-side request forgery (SSRF) flaw. Because the request_uri value is not validated against an allowlist, an unauthenticated remote party can make the Keycloak server issue outbound requests to arbitrary destinations.

5.3 CVSS 3.1 Medium EPSS 70% · top 0.6% CWE-918 · Server-side request forgery (SSRF)
5.3CVSS 3.1 base score, v2 5.0
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityThe flaw is remotely reachable without authentication or user interaction, public exploit code exists, and EPSS is very high, though CVSS impact is limited to low integrity.

What it is

Keycloak before 13.0.0 allows the OIDC request_uri parameter to force the server to fetch an unverified URL, resulting in a server-side request forgery (SSRF) flaw. Because the request_uri value is not validated against an allowlist, an unauthenticated remote party can make the Keycloak server issue outbound requests to arbitrary destinations.

Impact

An attacker can make the Keycloak server send requests to internal or external systems reachable from it, which can expose internal services or metadata endpoints and be used to probe or pivot into the internal network. The CVSS vector rates only low integrity impact and no confidentiality or availability impact, so direct data theft is not established by the record.

Attack surface

Reached over the network through the OIDC authentication endpoint by supplying a crafted request_uri parameter; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to trigger the outbound request.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at roughly 0.697 (99.3rd percentile), and public exploit references exist (Packet Storm, tagged Exploit). No ransomware usage is documented.

What to do

  • Upgrade Keycloak to 13.0.0 or later, which is the fixed version named in the advisory.
  • If immediate upgrade is not possible, restrict or disable use of the request_uri parameter and validate it against a strict allowlist of trusted URLs.
  • Apply network egress controls so the Keycloak server cannot reach internal metadata services, management interfaces, or other sensitive internal hosts.
  • Monitor and log outbound requests originating from Keycloak hosts to detect unexpected destinations.

Detection

  • Review Keycloak authentication logs for request_uri parameters containing external or internal IP addresses, localhost, or unusual hostnames.
  • Monitor outbound network traffic from Keycloak servers for connections to internal RFC1918 addresses, cloud metadata endpoints (169.254.169.254), or unexpected external hosts.
  • Alert on repeated or anomalous OIDC authorization requests that include request_uri values, especially from unauthenticated clients.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-10770 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-1245Redhat keycloak missing authorization vulnerabilityA privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac…EPSS 1.4%9.8CVE-2019-14910Redhat keycloak improper authentication vulnerabilityA vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…EPSS 1.1%9.6CVE-2021-20195Redhat keycloak improper input validation vulnerabilityA flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to …EPSS 1.2%9.1CVE-2022-3782Redhat keycloak path traversal vulnerabilitykeycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An a…EPSS 5.8%9.1CVE-2019-14837Redhat keycloak hard-coded credentials vulnerabilityA flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name …EPSS 1.7%8.8CVE-2026-3047Redhat build of keycloak vulnerabilityA flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider …EPSS 0.86%8.8CVE-2023-6787Redhat build of keycloak improper authentication vulnerabilityA flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijack…EPSS 0.74%8.8CVE-2023-4918Redhat keycloak cleartext transmission vulnerabilityA flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "pa…EPSS 0.57%

Source: NIST National Vulnerability Database (record CVE-2020-10770), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.