GHSA-jgwc-jh89-rpgq

Suggest an improvement
Source
https://github.com/advisories/GHSA-jgwc-jh89-rpgq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-jgwc-jh89-rpgq/GHSA-jgwc-jh89-rpgq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jgwc-jh89-rpgq
Aliases
Downstream
CGA (2)
ECHO (1)
Published
2024-11-25T19:39:12Z
Modified
2026-09-10T03:50:20Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 5.7 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Keycloak proxy header handling Denial-of-Service (DoS) vulnerability
Details

Keycloak versions 26 and earlier are vulnerable to a denial-of-service (DoS) attack through improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This can lead to costly DNS resolution operations, which an attacker could exploit to tie up IO threads and potentially cause a denial of service.

The attacker must have access to send requests to a Keycloak instance that is configured to accept proxy headers, specifically when reverse proxies do not overwrite incoming headers, and Keycloak is configured to trust these headers.

For Keycloak version 26, for successful exploitation includes: the realm must have SslRequired=EXTERNAL (the default), HTTP must be enabled, the instance must not be using a full hostname URL, access must come from behind a proxy (assuming the proxy overwrites the X-Forwarded-For header), and trusted proxies must not be set or must incorrectly trust the client from which the request is originating.

Database specific
{
    "cwe_ids":  [
        "CWE-444"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-11-25T19:39:12Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.keycloak:keycloak-quarkus-server

Package

Name
org.keycloak:keycloak-quarkus-server
View open source insights on deps.dev
Purl
pkg:maven/org.keycloak/keycloak-quarkus-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

12.*
12.0.0
12.0.1
12.0.2
12.0.3
12.0.4
13.*
13.0.0
13.0.1
14.*
14.0.0
15.*
15.0.0
15.0.1
15.0.2
15.1.0
15.1.1
16.*
16.0.0
16.1.0
16.1.1
17.*
17.0.0
17.0.1
18.*
18.0.0
18.0.1
18.0.2
19.*
19.0.0
19.0.1
19.0.2
19.0.3
20.*
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.0.5
21.*
21.0.0
21.0.1
21.0.2
21.1.0
21.1.1
21.1.2
22.*
22.0.0
22.0.1
22.0.2
22.0.3
22.0.4
22.0.5
23.*
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.0.6
23.0.7
24.*
24.0.0
24.0.1
24.0.2
24.0.3
24.0.4
24.0.5
25.*
25.0.0
25.0.1
25.0.2
25.0.3
25.0.4
25.0.5
25.0.6
26.*
26.0.0
26.0.1
26.0.2
26.0.4
26.0.5
26.0.6
26.0.7
26.0.8
26.1.0
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.2.0
26.2.1
26.2.2
26.2.3
26.2.4
26.2.5
26.3.0
26.3.1
26.3.2
26.3.3
26.3.4
26.3.5
26.4.0
26.4.1
26.4.2
26.4.3
26.4.4
26.4.5
26.4.6
26.4.7
26.5.0
26.5.1
26.5.2
26.5.3
26.5.4
26.5.5
26.5.6
26.5.7
26.6.0
26.6.1
26.6.2
26.6.3
26.6.4
26.7.0
26.7.1
26.7.2
26.7.3

Database specific

last_known_affected_version_range
"< 24.0.9"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-jgwc-jh89-rpgq/GHSA-jgwc-jh89-rpgq.json"

Maven / org.keycloak:keycloak-quarkus-server

Package

Name
org.keycloak:keycloak-quarkus-server
View open source insights on deps.dev
Purl
pkg:maven/org.keycloak/keycloak-quarkus-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
25.0.0
Fixed
26.0.6

Affected versions

25.*
25.0.0
25.0.1
25.0.2
25.0.3
25.0.4
25.0.5
25.0.6
26.*
26.0.0
26.0.1
26.0.2
26.0.4
26.0.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-jgwc-jh89-rpgq/GHSA-jgwc-jh89-rpgq.json"