RHSA-2025:15338MediumCVSS 5.3

Red Hat Security Advisory: Red Hat build of Keycloak 26.2.8 Images Security Update

Published
September 4, 2025
Last Modified
August 31, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-8419 — org.keycloak/keycloak-services: Keycloak SMTP Inject Vulnerability CVE-2025-9162 — org.keycloak/keycloak-model-storage-service: Variable injection into environment variables

🎯 Affected products10

  • Red Hat build of Keycloak 26.2
  • rhbk/keycloak-operator-bundle@sha256:fc20177b606cf759baa4d26819d2715ed4a4987debf776516dc6da597cafe0e7_amd64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:0eb95f916e9a5d339f1301104df6b1bbb4905214481ff7b02ae5b77d0499f4d3_s390x as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:daf94b071e1915aa8319f185900b1b8b070d144539a7e7b9c9fe9383d8277382_amd64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:e0dd6c0eb3f9562b0be5a90e913ff545a6f831738b30d174143ee9638c6548cc_ppc64le as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:f6b8e87369efe5ae0b36ff07b1cd281fff9a334cd0848cd736f6460155fa4dfd_arm64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:477f32910611a1ddfc2c6cb9308da981b2aba4c98275cc2658a10c711eca6c14_ppc64le as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:4f24bdc10102842c44b074d7f93d3b8fc9490565de1f2922824a47656e180251_amd64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:f145bae08c46626d732f4f9c244b1a83f812830f27be7a0682f3a42dd168ff03_s390x as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:fc5bc1a7a83016c5c2e13c006aa98cefb1812eb10dfb267aee15368e8540a7aa_arm64 as a component of Red Hat build of Keycloak 26.2

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Currently, no mitigation is available for this vulnerability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (4)