Skip to content

[GHSA-895x-rfqp-jh5c] Keycloak does not invalidate offline sessions when the offline_access scope is removed#6882

Open
eminaktas wants to merge 1 commit intoeminaktas/advisory-improvement-6882from
eminaktas-GHSA-895x-rfqp-jh5c
Open

[GHSA-895x-rfqp-jh5c] Keycloak does not invalidate offline sessions when the offline_access scope is removed#6882
eminaktas wants to merge 1 commit intoeminaktas/advisory-improvement-6882from
eminaktas-GHSA-895x-rfqp-jh5c

Conversation

@eminaktas
Copy link

@eminaktas eminaktas commented Feb 14, 2026

Updates

  • Affected products

Comments
This CVE is resolved for 26.2.3 and later 26.2.x versions: keycloak/keycloak@c830a27

@github-actions github-actions bot changed the base branch from main to eminaktas/advisory-improvement-6882 February 14, 2026 20:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant