CVE 5 MEDIUM

Keycloak-server: sensitive headers shown in the http access logs_CVE-2025-11537

5 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Description

A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.

Basic Information

ID CVE-2025-11537
Source redhat
Published Feb 10, 2026 at 10:53

Affected Product

Vendor Red Hat
Product Red Hat Build of Keycloak

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.