Out-of-bounds read in Red Hat build of Keycloak - CVE-2026-9803
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Keycloak\'s ClientRegistrationAuth component when processing a specially crafted POST request with a malformed Authorization: Bearer header at a client registration endpoint. A remote attacker can send a specially crafted POST request with a malformed Authorization: Bearer header to cause a denial of service.
The request can trigger an ArrayIndexOutOfBoundsException and an HTTP 500 error.