Class ClientHostUtils

java.lang.Object
org.keycloak.protocol.oidc.utils.ClientHostUtils

public class ClientHostUtils extends Object
Utility class for validating client host values against a client's registered URLs. Used to prevent SSRF attacks by ensuring that dynamic host values (like client_session_host) only reference hosts that are already configured and trusted for the client.

The trust model is: an administrator configures/opts in to create a client policy with the secure-client-node-hostname executor. This gates the register-node write endpoint against an admin-curated regex allowlist. Hostnames that pass that gate are stored in registeredNodes. This utility therefore treats registeredNodes as a pre-validated set and uses it (together with the management URL) as the source of allowed hosts for dynamic values such as client_session_host.

Resolves [CVE-2026-4874] Server-Side Request Forgery via OIDC token endpoint.

  • Constructor Details

    • ClientHostUtils

      public ClientHostUtils()
  • Method Details

    • isHostAllowedForClient

      public static boolean isHostAllowedForClient(String hostname, ClientModel client, KeycloakSession session)
      Validates that a hostname matches one of the client's registered nodes or the host component of the administrator-configured management URL.

      Registered nodes are trusted here; if the secure-client-node-hostname executor is active, hostnames will have been validated at registration time.

      Parameters:
      hostname - the hostname (or host:port) to validate
      client - the client model containing registered nodes and management URL
      session - the Keycloak session used for relative URL resolution
      Returns:
      true if the hostname matches a registered node or the management URL host, false otherwise
    • formatAsUriHost

      public static String formatAsUriHost(String host)