The Timestamp Keycloak Forgot to Check: CVE-2026-1190
Keycloak · SAML brokering · CVE-2026-1190 · CVSS 3.1 Low SAML has two places that tell you when an assertion stops being valid. Keycloak, acting as a SAML broker, checked one of them and quietly ignored the other. That is the whole bug.…