THREAT OPS › Threat News › [NVD] CVE-2026-0976 (LOW 3.7) — A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A remote attacker can craft requests to mask pa
[NVD] CVE-2026-0976 (LOW 3.7) — A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A remote attacker can craft requests to mask pa
CVE-2026-0976 CVSS: 3.7 LOW Published: 2026-01-15T13:16:04.910
A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A remote attacker can craft requests to mask path segments, potentially bypassing proxy-level path filt
Indicators of compromise
- CVE-2026-0976cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-0976