CVE-2024-11734
Java vulnerability analysis and mitigation

Overview

A denial of service vulnerability (CVE-2024-11734) was discovered in Keycloak that affects administrative users with realm settings modification privileges. The vulnerability was disclosed on January 14, 2025, and affects the Keycloak server software. This security issue has been classified with a CVSS v3.1 base score of 6.5 (Medium) (NVD, Red Hat Advisory).

Technical details

The vulnerability occurs when an administrative user modifies security headers by inserting newlines. This action causes the Keycloak server to attempt writing to a request that has already been terminated, resulting in request failure. The vulnerability has been assigned a CVSS vector string of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating network accessibility, low attack complexity, and high impact on availability (NVD).

Impact

When exploited, this vulnerability can cause service disruption, preventing users from accessing applications that rely on Keycloak authentication or any of the consoles provided by Keycloak itself on the affected realm. The impact is limited to availability, with no direct effect on confidentiality or integrity (Red Hat Bugzilla).

Exploitability

The vulnerability requires an administrative user account with specific privileges to modify realm settings. The attack vector is network-accessible, but the prerequisite of administrative access limits the potential for widespread exploitation (NVD).

Mitigation and workarounds

Red Hat has addressed this vulnerability in Keycloak version 26.0.8. Updates are available through security advisories RHSA-2025:0299 and RHSA-2025:0300. Users are advised to upgrade to the latest version to mitigate this security issue (Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76904CRITICAL9.8
  • Java logoJava
  • org.geotools.jdbc:gt-jdbc-postgis
NoYesAug 21, 2026
GHSA-mqjf-5f49-2fjhCRITICAL9.8
  • Java logoJava
  • org.geotools:gt-jdbc-postgis
NoYesAug 21, 2026
CVE-2026-61827HIGH8.7
  • Java logoJava
  • io.netty.incubator:netty-incubator-codec-bhttp
NoYesAug 20, 2026
CVE-2026-63202HIGH7.5
  • Java logoJava
  • io.netty.incubator:netty-incubator-codec-bhttp
NoYesAug 20, 2026
CVE-2026-63124HIGH7.5
  • Java logoJava
  • io.netty.incubator:netty-incubator-codec-bhttp
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management