Junglewise Threat Intelligence

CVE-2026-0707: Keycloak permissive Authorization header parsing bypass

CVE-2026-0707 · Severity: medium · CVSS 5.3 · Published 2026-01-08

Technologies: org.keycloak:keycloak-parent (Maven), Red Hat build of Keycloak, Keycloak. Vendors: Maven, Red Hat, Keycloak.

Executive brief

Keycloak is an open-source identity and access management solution used to secure applications and services. A flaw in how it processes authentication headers allows it to accept non-standard formatting, such as extra spaces or tabs, when identifying security tokens. This inconsistency can allow an attacker to bypass security filters like Web Application Firewalls (WAFs) that expect strict adherence to standards, potentially leading to unauthorized access.

Technical details

A vulnerability exists in Keycloak's Authorization header parsing logic (CWE-551). The parser is overly permissive regarding the 'Bearer' authentication scheme, accepting non-standard separators (such as tab characters, multiple spaces, or mixed whitespace) and case variations that deviate from RFC 6750. This behavior creates a discrepancy between Keycloak and front-end security controls like Web Application Firewalls (WAFs) or reverse proxies. An attacker can exploit this 'impedance mismatch' to smuggle authentication headers past security filters that do not recognize the malformed syntax, while Keycloak still processes them as valid, potentially bypassing intended security policies. The issue is addressed in Red Hat build of Keycloak 26.4.10.

Affected products

  • Keycloak Keycloak <= 26.5.0
  • Red Hat Red Hat build of Keycloak < 26.4.10

Timeline

  • 2026-01-08: disclosed
  • 2026-01-08: advisory
  • 2026-03-05: patched: Red Hat released patches for Red Hat build of Keycloak

References

Related threats