Vulnerability in Keycloak's Authorization Header Parser Affects Authentication Security
CVE-2026-0707

5.3MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
8 January 2026

What is CVE-2026-0707?

A security flaw in Keycloak's authorization header parser allows for overly permissive input, which compromises authentication mechanisms. The parser accepts non-standard characters, including tabs, as delimiters for the 'Bearer' authentication scheme. Additionally, it exhibits leniency with case variations that deviate from the specifications set out in RFC 6750. This could potentially enable attackers to exploit authentication processes, leading to unauthorized access.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Guanping Zhang for reporting this issue.
.