RHSA-2025:11986MediumCVSS 7.1
Red Hat Security Advisory: Red Hat build of Keycloak 26.0.13 Images Update
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-7365 — keycloak: Phishing attack via email verification step in first login flow
🎯 Affected products8
- Red Hat build of Keycloak 26.0
- rhbk/keycloak-operator-bundle@sha256:cc408742b3dc427140802b34db0b58ebc7fda4375b9363b105552967dc444c70_amd64 as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9-operator@sha256:1c5afe893168d78648f5d9485e81362416c38b03749d9e5df1b3cd1b90fb6ffd_ppc64le as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9-operator@sha256:b622c781d0d7a8a0cf6f4f2c62d3d860a6afb8f3442822a3cc9388384e7dd0c9_s390x as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9-operator@sha256:c945dcf47b0da10011a28be1643cc0ef5eb100fa02bc882dc5b32466afb22f7c_amd64 as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9@sha256:4da4de30a72187fd31ce42993cd36254571f98ff3fcf6e6c0575e9f33bdb9566_amd64 as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9@sha256:7851520291345ab2fe693ba86cfab7a4c4333d1b10526585f49a8ebf1a77f8b6_ppc64le as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9@sha256:e8b0d6f3ac5d577beefeceec300cb1e63ca2ff370ac97f45b6d7ec485d56d305_s390x as a component of Red Hat build of Keycloak 26.0
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Disable account review in the Identity Provider to prevent users from potentially modifying identity information. Disable the email verification step and use only re-authentication step.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2025:11986
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2378852
- externalhttps://issues.redhat.com/browse/RHBK-3137
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_11986.json