Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cpf7-j4cf-vqx4

Опубликовано: 28 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Keycloak has an Out-of-bounds Read

A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authorization: Bearer' header to any client registration endpoint. This can lead to an ArrayIndexOutOfBoundsException, causing the server to return an HTTP 500 error and resulting in a Denial of Service (DoS) for the affected service.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

<= 26.4.7

Отсутствует

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

>= 26.5.0, < 26.6.3

26.6.3

EPSS

Процентиль: 31%
0.00389
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 5.3
redhat
2 месяца назад

A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authorization: Bearer' header to any client registration endpoint. This can lead to an ArrayIndexOutOfBoundsException, causing the server to return an HTTP 500 error and resulting in a Denial of Service (DoS) for the affected service.

CVSS3: 5.3
nvd
2 месяца назад

A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authorization: Bearer' header to any client registration endpoint. This can lead to an ArrayIndexOutOfBoundsException, causing the server to return an HTTP 500 error and resulting in a Denial of Service (DoS) for the affected service.

CVSS3: 5.3
debian
2 месяца назад

A flaw was found in Keycloak's ClientRegistrationAuth component. A rem ...

EPSS

Процентиль: 31%
0.00389
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-125