{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-1518","assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","state":"REJECTED","assignerShortName":"redhat","dateReserved":"2026-01-28T08:08:15.419Z","datePublished":"2026-02-02T07:17:46.557Z","dateUpdated":"2026-07-24T14:07:33.181Z","dateRejected":"2026-07-24T14:07:33.181Z"},"containers":{"cna":{"rejectedReasons":[{"lang":"en","value":"DO NOT USE THIS CANDIDATE NUMBER. After further review by the Keycloak project and Red Hat, the reported SSRF via client registration/backchannel notification URIs was determined not to constitute a security vulnerability. The reported behavior is expected administrator-controlled functionality, and Keycloak provides documented mitigations through Client Policies, including the Secure Client URIs Pattern executor. Therefore, this CVE has been rejected."}],"providerMetadata":{"orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat","dateUpdated":"2026-07-24T14:07:33.181Z"}}}}