Resource exhaustion in Keycloak - #VU146998
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of malformed Authorization headers in ClientRegistrationAuth when processing client registration authentication requests. A remote attacker can send a malformed Authorization header to cause a denial of service.
This issue is an incomplete fix for CVE-2026-0707.