CVE-2024-9666: Red Hat Build Of Keycloak

Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This issue can lead to costly DNS resolution operations, which an attacker could exploit to tie up IO threads and potentially cause a denial of service. The attacker must have access to send requests to a Keycloak instance that is configured to accept proxy headers, specifically when reverse proxies do not overwrite incoming headers, and Keycloak is configured to trust these headers.

Affected products

  • Red Hat Red Hat Build Of Keycloak
  • Red Hat Red Hat Build Of Keycloak 24: before 24.0.9-1 (fixed in 24.0.9-1); before 24-18 (fixed in 24-18)
  • Red Hat Red Hat Build Of Keycloak 24.0.9
  • Red Hat Red Hat Build Of Keycloak 26.0: before 26.0.6-2 (fixed in 26.0.6-2); before 26.0-5 (fixed in 26.0-5); before 26.0-6 (fixed in 26.0-6)
  • Red Hat Red Hat Build Of Keycloak 26.0.6
  • Red Hat Red Hat JBoss Enterprise Application Platform 8

Published 2024-11-25. Last modified 2026-09-21.