PT-2026-30582 · Red Hat · Keycloak

Osidb Bzimport

·

Published

2026-04-06

·

Updated

2026-04-06

·

CVE-2026-37977

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in Keycloak that allows a remote attacker to exploit a Cross-Origin Resource Sharing (CORS) header injection in the User-Managed Access (UMA) token endpoint. The issue arises because the azp claim from a client-supplied JSON Web Token (JWT) is used to set the Access-Control-Allow-Origin header before JWT signature validation. A crafted JWT with a controlled azp value can be reflected as the CORS origin, potentially exposing low-sensitivity information from authorization server error responses, but only when a client is misconfigured with webOrigins: ['*'].
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2026-37977
GHSA-5V8V-XVJV-57X7

Affected Products

Keycloak