Junglewise Threat Intelligence

CVE-2026-37977: Keycloak CORS header injection in UMA token endpoint

CVE-2026-37977 · Severity: low · CVSS 3.7 · Published 2026-04-06

Technologies: Keycloak-Services. Vendors: Keycloak.

Executive brief

Keycloak, an open-source identity and access management solution, is vulnerable to a minor information disclosure flaw. An attacker can manipulate security headers to potentially view error messages from the authorization server that should normally be restricted. This issue primarily affects systems where the software has been specifically misconfigured to allow all web origins.

Technical details

A flaw in Keycloak's User-Managed Access (UMA) token endpoint allows for Cross-Origin Resource Sharing (CORS) header injection. The root cause is that the 'azp' (authorized party) claim from a client-supplied JSON Web Token (JWT) is used to populate the 'Access-Control-Allow-Origin' header before the JWT's signature is validated. An attacker can provide a crafted JWT with a malicious 'azp' value, which is then reflected in the response header even if the request is eventually rejected. This can lead to the exposure of low-sensitivity information from error responses, though it requires the target client to be misconfigured with 'webOrigins: ["*"]'. Patches are available in versions 26.4.13 and 26.6.3.

Affected products

  • Keycloak keycloak-services < 26.4.13, >= 26.5.0, < 26.6.3

Timeline

  • 2026-04-06: disclosed
  • 2026-04-06: advisory

References

Related threats