RHSA-2025:2544MediumCVSS 5.4

Red Hat Security Advisory: Red Hat build of Keycloak 26.0.10 Images Update

Published
March 10, 2025
Last Modified
July 30, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-0604 — keycloak-ldap-federation: Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak CVE-2025-1391 — keycloak-services: Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims

🎯 Affected products8

  • Red Hat build of Keycloak 26.0
  • rhbk/keycloak-operator-bundle@sha256:d719dbf646d4c66e9fce35418a90bffc6ae4f40bdf7d7c306fb903f6f1bce14f_amd64 as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9-operator@sha256:2cf74d2886063637b9c0bf1fe5d97866b8dcac8aa5c00b064790b8133fef676b_ppc64le as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9-operator@sha256:73097189922c29afdbb6890ebc2b3e276ab6fbfe81bc0d74d0c5268783c1e806_amd64 as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9-operator@sha256:ed9cad42ed11212bf7a8dc7d6afbcc52cd76082f87fae5c0f923dcc70fc1a444_s390x as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9@sha256:2cb3de99006ef0d9cf53955880c6eff3dbe5de5e7f9e6ddbb5e5b0bb828789ca_ppc64le as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9@sha256:42cf4d4f9576ad1a3b54b10a9f022f9f7ded8f98804da66dad51625c8aa868aa_amd64 as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9@sha256:835ced3d703edf1fa55d563e12049b30ef60f4450f0cc4af8e2ff53e34896657_s390x as a component of Red Hat build of Keycloak 26.0

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

🔗 References (5)