CVE-2025-11537
A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
- EPSS probability
- 0.15%
- CWE
- CWE-117
- Published
- 2026-02-10
- Last modified
- 2026-09-04
Weakness type
Related vulnerabilities
- CVE-2026-25548 — InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoning
- CVE-2024-47083 — Power Platform Terraform Provider has Improper Masking of Secrets in Logs
- CVE-2024-29022 — Session Hijacking via XSS attack in header and session grid in Xibo CMS
- CVE-2023-32712 — Unauthenticated Log Injection in Splunk Enterprise
- CVE-2024-25047 — IBM Cognos Analytics log injection
- CVE-2023-4571 — Unauthenticated Log Injection in Splunk IT Service Intelligence (ITSI)
- CVE-2023-3997 — Unauthenticated Log Injection In Splunk SOAR
- CVE-2026-62948 — OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI