CVE-2026-0976

A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A remote attacker can craft requests to mask path segments, potentially bypassing proxy-level path filtering. This could expose administrative or sensitive endpoints that operators believe are not externally reachable.
Configurations

No configuration.

History

15 Jan 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 13:16

Updated : 2026-01-16 15:55


NVD link : CVE-2026-0976

Mitre link : CVE-2026-0976

CVE.ORG link : CVE-2026-0976


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation