A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.
History

Tue, 10 Feb 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Vendors & Products Redhat build Of Keycloak

Tue, 10 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Feb 2026 11:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.
Title Keycloak-server: sensitive headers shown in the http access logs
First Time appeared Redhat
Redhat build Keycloak
Weaknesses CWE-117
CPEs cpe:/a:redhat:build_keycloak:
Vendors & Products Redhat
Redhat build Keycloak
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-02-10T14:32:29.177Z

Reserved: 2025-10-09T01:26:22.026Z

Link: CVE-2025-11537

cve-icon Vulnrichment

Updated: 2026-02-10T14:32:23.365Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-10T11:16:09.397

Modified: 2026-02-10T15:22:54.740

Link: CVE-2025-11537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-10T15:37:12Z