Vulnerability in Keycloak's Authorization Header Parser Affects Authentication Security
CVE-2026-0707
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 8 January 2026
What is CVE-2026-0707?
A security flaw in Keycloak's authorization header parser allows for overly permissive input, which compromises authentication mechanisms. The parser accepts non-standard characters, including tabs, as delimiters for the 'Bearer' authentication scheme. Additionally, it exhibits leniency with case variations that deviate from the specifications set out in RFC 6750. This could potentially enable attackers to exploit authentication processes, leading to unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Red Hat build of Keycloak 26.4 26.4.10-1
Red Hat build of Keycloak 26.4 26.4-12
Red Hat build of Keycloak 26.4 26.4-12
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved