RHSA-2025:15337MediumCVSS 5.3

Red Hat Security Advisory: Red Hat build of Keycloak 26.0.15 Images Update

Published
September 4, 2025
Last Modified
August 31, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-8419 — org.keycloak/keycloak-services: Keycloak SMTP Inject Vulnerability CVE-2025-9162 — org.keycloak/keycloak-model-storage-service: Variable injection into environment variables

🎯 Affected products8

  • Red Hat build of Keycloak 26.0
  • rhbk/keycloak-operator-bundle@sha256:74775c7851ac98ba2903435c71b9d02cc504ca8ee98b65ad7282d671392756a6_amd64 as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9-operator@sha256:46c10d58dadab4be33f0c5a258ddaa1e5d1f52f849eb80d94af56cb5c2383070_amd64 as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9-operator@sha256:c0e92f4dbb5731a00892e9638bab32e7a7071e282d35cd601bfd67be1f3bfab9_ppc64le as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9-operator@sha256:ffdae6b06aa17794c81938cab48f4f174fa7dbdfe6ef6b0b37639b72408eb5bd_s390x as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9@sha256:303763107515e2186a3201f979cb6953e2fccdc32278bec4700f424cf81536e7_s390x as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9@sha256:fa4c28db99a6cc4bb8729dceb023ac0c3c5a40e4f4e6d205aa6cd15935357ffb_amd64 as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9@sha256:ff313047a67cae72ae7dded6969344541b4e7aa074a80105cd40f42972b69a8b_ppc64le as a component of Red Hat build of Keycloak 26.0

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Currently, no mitigation is available for this vulnerability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (4)