Vulnerability in Keycloak's Authorization Header Parser Affects Authentication Security
CVE-2026-0707
5.3MEDIUM
What is CVE-2026-0707?
A security flaw in Keycloak's authorization header parser allows for overly permissive input, which compromises authentication mechanisms. The parser accepts non-standard characters, including tabs, as delimiters for the 'Bearer' authentication scheme. Additionally, it exhibits leniency with case variations that deviate from the specifications set out in RFC 6750. This could potentially enable attackers to exploit authentication processes, leading to unauthorized access.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Guanping Zhang for reporting this issue.