REDHAT-BUG-2482465
A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authorization: Bearer' header to any client registration endpoint. This can lead to an ArrayIndexOutOfBoundsException, causing the server to return an HTTP 500 error and resulting in a Denial of Service (DoS) for the affected service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2482465?
The severity of REDHAT-BUG-2482465 is rated as medium with a score of 4.
How can I fix REDHAT-BUG-2482465?
To fix REDHAT-BUG-2482465, update Keycloak to the latest version where this vulnerability has been addressed.
What impact does REDHAT-BUG-2482465 have on Keycloak?
REDHAT-BUG-2482465 allows a remote unauthenticated attacker to exploit Keycloak by sending specially crafted POST requests, potentially causing an ArrayIndexOutOfBounds exception.
Who is affected by REDHAT-BUG-2482465?
Any installation of Keycloak that exposes client registration endpoints is potentially vulnerable to REDHAT-BUG-2482465.
When was REDHAT-BUG-2482465 published?
REDHAT-BUG-2482465 was published on May 28, 2026.