"value":"A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This issue can lead to costly DNS resolution operations, which an attacker could exploit to tie up IO threads and potentially cause a denial of service.\nThe attacker must have access to send requests to a Keycloak instance that is configured to accept proxy headers, specifically when reverse proxies do not overwrite incoming headers, and Keycloak is configured to trust these headers."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')",
"cweId":"CWE-444"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"Red Hat",
"product":{
"product_data":[
{
"product_name":"Red Hat build of Keycloak 24",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"24.0.9-1",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"24-18",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"24-18",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
}
]
}
},
{
"product_name":"Red Hat build of Keycloak 24.0.9",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unaffected"
}
}
]
}
},
{
"product_name":"Red Hat build of Keycloak 26.0",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"26.0.6-2",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"26.0-5",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"26.0-6",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
}
]
}
},
{
"product_name":"Red Hat build of Keycloak 26.0.6",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unaffected"
}
}
]
}
},
{
"product_name":"Red Hat JBoss Enterprise Application Platform 8",