Incorrect Behavior Order: Authorization Before Parsing and Canonicalization Affecting org.keycloak:keycloak-services package, versions [9.0.0,26.5.4)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGKEYCLOAK-14912583
  • published11 Jan 2026
  • disclosed8 Jan 2026
  • creditUnknown

Introduced: 8 Jan 2026

CVE-2026-0707  (opens in a new tab)
CWE-551  (opens in a new tab)

How to fix?

Upgrade org.keycloak:keycloak-services to version 26.5.4 or higher.

Overview

org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services.

Affected versions of this package are vulnerable to Incorrect Behavior Order: Authorization Before Parsing and Canonicalization due to the Authorization header parser accepting non-standard characters as separators and tolerating case variations that do not comply with RFC 6750 specifications. An attacker can bypass intended access restrictions by crafting specially formatted authentication headers.

CVSS Base Scores

version 4.0
version 3.1