A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A remote attacker can craft requests to mask path segments, potentially bypassing proxy-level path filtering. This could expose administrative or sensitive endpoints that operators believe are not externally reachable.
References
Configurations
No configuration.
History
15 Jan 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-15 13:16
Updated : 2026-01-16 15:55
NVD link : CVE-2026-0976
Mitre link : CVE-2026-0976
CVE.ORG link : CVE-2026-0976
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
