PT-2024-39748 · Red Hat+1 · Keycloak Server+2
CVE-2024-9666
·
Published
2024-10-08
·
Updated
2026-08-31
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Keycloak versions 26 and earlier
Description
Keycloak Server is susceptible to a denial of service (DoS) attack due to improper handling of proxy headers. When configured to accept incoming proxy headers, the server may accept non-IP values, such as obfuscated identifiers, without adequate validation. This flaw can trigger expensive DNS resolution operations, allowing an attacker to tie up IO threads and potentially crash the service. Exploitation requires the ability to send requests to an instance configured to trust proxy headers, particularly when reverse proxies do not overwrite incoming headers. For version 26, successful exploitation also requires the realm to have
SslRequired set to EXTERNAL, HTTP enabled, the instance not using a full hostname URL, and trusted proxies to be either unset or incorrectly configured to trust the originating client.Recommendations
Update Keycloak to version 26.1.2-alt1 or later.
Update Keycloak to version 26.4.0-alt1 or later.
Configure reverse proxies to overwrite incoming proxy headers to prevent the server from processing untrusted values.
Exploit
Fix
DoS
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Keycloak
Keycloak Server