CVE-2024-11734
Executive Summary
CVE‑2024‑11734 is a denial‑of‑service flaw in Keycloak that allows an admin with realm‑settings privileges to inject newline characters into security‑header values. The malformed header causes the server to write to a closed request, aborting the transaction and potentially rendering the realm inoperable. The issue is exploitable only by users with administrative rights and does not involve remote code execution or data exfiltration.
Authoritative CVE Metadata - CVSS Base Score: 6.5 (MEDIUM) - Published: 2025-01-14T09:15:19.443 - Last Modified: 2026-08-31T01:16:43.687
Original Description: A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.
"I believe that a simple and unassuming manner of life is best for everyone, best both for the body and the mind."
— Albert Einstein