Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 Maven

Keycloak has Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

GHSA-gv94-wp4h-vv8p · CVE-2026-0707

Published · Modified

Description

A flaw was found in Keycloak. The Keycloak Authorization header parser is overly permissive regarding the formatting of the "Bearer" authentication scheme. It accepts non-standard characters (such as tabs) as separators and tolerates case variations that deviate from RFC 6750 specifications.

Ready to move

Start Securing

Free, no credit card | First findings in minutes