PT-2026-1976 · Red Hat · Keycloak

Guanping Zhang

·

Published

2026-01-08

·

Updated

2026-03-05

·

CVE-2026-0707

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description The Keycloak Authorization header parser is overly permissive regarding the formatting of the "Bearer" authentication scheme. It accepts non-standard characters, such as tabs, as separators and tolerates case variations that deviate from RFC 6750 specifications. This could potentially lead to a security control bypass.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2026-0707
GHSA-GV94-WP4H-VV8P

Affected Products

Keycloak