CVE-2024-11734
Java vulnerability analysis and mitigation

Overview

A denial of service vulnerability (CVE-2024-11734) was discovered in Keycloak that affects administrative users with realm settings modification privileges. The vulnerability was disclosed on January 14, 2025, and affects the Keycloak server software. This security issue has been classified with a CVSS v3.1 base score of 6.5 (Medium) (NVD, Red Hat Advisory).

Technical details

The vulnerability occurs when an administrative user modifies security headers by inserting newlines. This action causes the Keycloak server to attempt writing to a request that has already been terminated, resulting in request failure. The vulnerability has been assigned a CVSS vector string of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating network accessibility, low attack complexity, and high impact on availability (NVD).

Impact

When exploited, this vulnerability can cause service disruption, preventing users from accessing applications that rely on Keycloak authentication or any of the consoles provided by Keycloak itself on the affected realm. The impact is limited to availability, with no direct effect on confidentiality or integrity (Red Hat Bugzilla).

Mitigation and workarounds

Red Hat has addressed this vulnerability in Keycloak version 26.0.8. Updates are available through security advisories RHSA-2025:0299 and RHSA-2025:0300. Users are advised to upgrade to the latest version to mitigate this security issue (Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68113MEDIUM6.5
  • JavaScriptJavaScript
  • altcha-org/altcha
NoYesDec 16, 2025
CVE-2025-67735MEDIUM6.5
  • JavaJava
  • io.netty:netty-codec-http
NoYesDec 16, 2025
CVE-2025-67721MEDIUM6.3
  • JavaJava
  • io.airlift:aircompressor-v3
NoYesDec 12, 2025
CVE-2025-53960MEDIUM5.9
  • JavaJava
  • org.apache.streampark:streampark
NoYesDec 12, 2025
CVE-2025-14674MEDIUM5.3
  • JavaJava
  • com.aizuda:snail-job
NoYesDec 14, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management