PT-2024-39748 · Red Hat+1 · Keycloak Server+2

CVE-2024-9666

·

Published

2024-10-08

·

Updated

2026-08-31

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Keycloak versions 26 and earlier
Description Keycloak Server is susceptible to a denial of service (DoS) attack due to improper handling of proxy headers. When configured to accept incoming proxy headers, the server may accept non-IP values, such as obfuscated identifiers, without adequate validation. This flaw can trigger expensive DNS resolution operations, allowing an attacker to tie up IO threads and potentially crash the service. Exploitation requires the ability to send requests to an instance configured to trust proxy headers, particularly when reverse proxies do not overwrite incoming headers. For version 26, successful exploitation also requires the realm to have SslRequired set to EXTERNAL, HTTP enabled, the instance not using a full hostname URL, and trusted proxies to be either unset or incorrectly configured to trust the originating client.
Recommendations Update Keycloak to version 26.1.2-alt1 or later. Update Keycloak to version 26.4.0-alt1 or later. Configure reverse proxies to overwrite incoming proxy headers to prevent the server from processing untrusted values.

Exploit

Fix

DoS

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-13422
ALT-PU-2025-2871
BDU:2025-02197
CVE-2024-9666
ECHO-7EDB-23C5-02EC
GHSA-JGWC-JH89-RPGQ
GHSA-PCX7-8HXG-J823

Affected Products

Alt Linux
Keycloak
Keycloak Server