Skip to content

[CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverified JWT azp claim on UMA token endpoint#49512

Merged
ahus1 merged 1 commit into
keycloak:mainfrom
pedroigor:issue-48036
Jun 2, 2026
Merged

[CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverified JWT azp claim on UMA token endpoint#49512
ahus1 merged 1 commit into
keycloak:mainfrom
pedroigor:issue-48036

Conversation

@pedroigor

Copy link
Copy Markdown
Contributor

Closes #48036

…rified JWT azp claim on UMA token endpoint

Closes keycloak#48036

Signed-off-by: Pedro Igor <pigor.craveiro@gmail.com>
@pedroigor pedroigor requested review from a team as code owners May 29, 2026 17:39
@ahus1 ahus1 merged commit 461ce79 into keycloak:main Jun 2, 2026
95 of 97 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverified JWT azp claim on UMA token endpoint

3 participants