CVE 3.1 LOW

Org.keycloak.protocol.oidc: keycloak refresh token reuse bypass via toctou race condition_CVE-2026-1035

3.1 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Description

A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not performed atomically. This allows concurrent refresh requests to bypass single-use enforcement and issue multiple access tokens from the same refresh token. As a result, Keycloak’s refresh token rotation hardening can be undermined.

Basic Information

ID CVE-2026-1035
Source redhat
Published Jan 21, 2026 at 05:52

Affected Product

Vendor Red Hat
Product Red Hat Build of Keycloak

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.