A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.

Project Subscriptions

Vendors Products
Build Keycloak Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

History

Tue, 10 Feb 2026 11:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.
Title Keycloak-server: sensitive headers shown in the http access logs
First Time appeared Redhat
Redhat build Keycloak
Weaknesses CWE-117
CPEs cpe:/a:redhat:build_keycloak:
Vendors & Products Redhat
Redhat build Keycloak
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-02-10T14:32:29.177Z

Reserved: 2025-10-09T01:26:22.026Z

Link: CVE-2025-11537

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-10T11:16:09.397

Modified: 2026-02-10T11:16:09.397

Link: CVE-2025-11537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses