Thanks to visit codestin.com
Credit goes to github.com

Skip to content

CVE-2026-0707: Keycloak Authorization Header Parsing Leading to Potential Security Control Bypass #45649

@abstractj

Description

@abstractj

Source: https://issues.redhat.com/browse/RHBK-4088

Security Tracking Issue

Flaw:

Keycloak Authorization Header Parsing Leading to Potential Security Control Bypass

Keycloak’s authentication pipeline excessively tolerates non-standard Bearer token formats (case variations, Tab characters, multiple spaces, mixed whitespace) in the Authorization header, creating inconsistencies with front-end security controls (WAF/proxies) and enabling potential bypass risks.


This issue was originally tracked in the private repository as #309. Migrated via lift-embargo process.

Metadata

Metadata

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions