CVE-2024-9666: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This issue can lead to costly DNS resolution operations, which an attacker could exploit to tie up IO threads and potentially cause a denial of service. The attacker must have access to send requests to a Keycloak instance that is configured to accept proxy headers, specifically when reverse proxies do not overwrite incoming headers, and Keycloak is configured to trust these headers.
AI Analysis
Technical Summary
Keycloak Server improperly handles proxy headers when configured to accept and trust them, allowing an attacker to supply non-IP values such as obfuscated identifiers. This leads to expensive DNS resolution attempts that consume IO threads, potentially causing denial of service. The vulnerability is exploitable only if Keycloak is configured to trust proxy headers and the reverse proxy does not overwrite incoming headers. Red Hat advisories (RHSA-2024:10175, RHSA-2024:10176, and others) provide updated Keycloak 24.0.9 images that fix this issue.
Potential Impact
An attacker with the ability to send requests to a vulnerable Keycloak instance can cause denial of service by exhausting IO threads through forced DNS resolution operations triggered by malformed proxy headers. There is no impact on confidentiality or integrity reported. The vulnerability requires specific configuration conditions to be exploitable.
Mitigation Recommendations
Red Hat has released updated Keycloak 24.0.9 images that address this vulnerability. Users should apply these updates as provided in the Red Hat advisories RHSA-2024:10175 and RHSA-2024:10176. Before updating, back up existing installations including configurations and databases. Patch status is official-fix via these vendor updates.
CVE-2024-9666: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Description
A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This issue can lead to costly DNS resolution operations, which an attacker could exploit to tie up IO threads and potentially cause a denial of service. The attacker must have access to send requests to a Keycloak instance that is configured to accept proxy headers, specifically when reverse proxies do not overwrite incoming headers, and Keycloak is configured to trust these headers.
CVSS v3.1
Score 4.7medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Keycloak Server improperly handles proxy headers when configured to accept and trust them, allowing an attacker to supply non-IP values such as obfuscated identifiers. This leads to expensive DNS resolution attempts that consume IO threads, potentially causing denial of service. The vulnerability is exploitable only if Keycloak is configured to trust proxy headers and the reverse proxy does not overwrite incoming headers. Red Hat advisories (RHSA-2024:10175, RHSA-2024:10176, and others) provide updated Keycloak 24.0.9 images that fix this issue.
Potential Impact
An attacker with the ability to send requests to a vulnerable Keycloak instance can cause denial of service by exhausting IO threads through forced DNS resolution operations triggered by malformed proxy headers. There is no impact on confidentiality or integrity reported. The vulnerability requires specific configuration conditions to be exploitable.
Mitigation Recommendations
Red Hat has released updated Keycloak 24.0.9 images that address this vulnerability. Users should apply these updates as provided in the Red Hat advisories RHSA-2024:10175 and RHSA-2024:10176. Before updating, back up existing installations including configurations and databases. Patch status is official-fix via these vendor updates.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- redhat
- Date Reserved
- 2024-10-08T22:36:23.598Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2024:10175","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:10176","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:10177","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:10178","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2024-9666","vendor":"Red Hat"}]
Threat ID: 68e0f3c4b66c7f7acdd3ea2e
Added to database: 10/04/2025, 10:15:32 UTC
Last enriched: 08/11/2026, 18:04:44 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 244
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.