RHSA-2025:22088MediumCVSS 6.0

Red Hat Security Advisory: Red Hat build of Keycloak 26.2.11 Images Security Update

Published
November 25, 2025
Last Modified
August 4, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2025-11429 — keycloak-server: Too long and not settings compliant session CVE-2025-12110 — keycloak: org.keycloak:keycloak-services: User can refresh offline session even after client's offline_access scope was removed CVE-2025-12150 — org.keycloak/keycloak-services: WebAuthn Attestation Statement Verification Bypass CVE-2025-12390 — org.keycloak.protocol.oidc.endpoints.LogoutEndpoint: Offline Session takeover due to reused Authentication Session ID CVE-2025-13467 — org.keycloak.storage.ldap: Keycloak: Deserialization of Untrusted Data in LDAP User Federation

🎯 Affected products10

  • Red Hat build of Keycloak 26.2
  • rhbk/keycloak-operator-bundle@sha256:dbebd9c370278ca9745863823ea05be8026400f70ada7650d65ef381841bfc5b_amd64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:56c72c8a7c8fc6dc429272f50d1ca7d2c1f3c20819f86c314ecd16df7067f348_s390x as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:57d64e64c4b64a802faf366d4e156d01b04c2fbb3d866b123ac4c2f82968a46f_arm64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:b9525ea17de357c938972cc8c6cf78ba1fc1902901e1759908e9fcb2c0e72aed_amd64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:d7602888e037d4d5bba73f896e4537721130464ef82406c31a445701f015f93b_ppc64le as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:31618f217a7d9a08945106f507dd0ca02b3850d183c4915311203423204a4c03_s390x as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:527c210541d8669a7b08029be54f411512f14fe887d92569801e8801f8c001f5_amd64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:8c52f172dd64c5d4a4078a3d9af16612151607332eea832c6ded4600d71c68ca_ppc64le as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:c9da93981df5435ded6a22b5a36876c4a10f66ebc4d4f91fdd9e2084e6b60a2f_arm64 as a component of Red Hat build of Keycloak 26.2

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (3)