A flaw was found in Keycloak. The Keycloak Authorization header parser is overly permissive regarding the formatting of the "Bearer" authentication scheme. It accepts non-standard characters (such as tabs) as separators and tolerates case variations that deviate from RFC 6750 specifications.
{
"cwe_ids": [
"CWE-551"
],
"severity": "MODERATE",
"nvd_published_at": "2026-01-08T04:15:56Z",
"github_reviewed": true,
"github_reviewed_at": "2026-01-08T21:14:12Z"
}