-
Notifications
You must be signed in to change notification settings - Fork 8.1k
Labels
kind/cveIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedpriority/importantMust be worked on very soonMust be worked on very soonrelease/26.4.10release/26.5.4release/26.6.0team/core-clients
Description
Source: https://issues.redhat.com/browse/RHBK-4088
Security Tracking Issue
Flaw:
Keycloak Authorization Header Parsing Leading to Potential Security Control Bypass
Keycloak’s authentication pipeline excessively tolerates non-standard Bearer token formats (case variations, Tab characters, multiple spaces, mixed whitespace) in the Authorization header, creating inconsistencies with front-end security controls (WAF/proxies) and enabling potential bypass risks.
This issue was originally tracked in the private repository as #309. Migrated via lift-embargo process.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
kind/cveIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedpriority/importantMust be worked on very soonMust be worked on very soonrelease/26.4.10release/26.5.4release/26.6.0team/core-clients