RHSA-2025:4335HighCVSS 8.2
Red Hat Security Advisory: Red Hat build of Keycloak 26.0.11 Images Update
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-2559 — org.keycloak/keycloak-services: JWT Token Cache Exhaustion Leading to Denial of Service (DoS) in Keycloak CVE-2025-3501 — org.keycloak.protocol.services: Keycloak hostname verification CVE-2025-3910 — org.keycloak.authentication: Two factor authentication bypass
🎯 Affected products8
- Red Hat build of Keycloak 26.0
- rhbk/keycloak-operator-bundle@sha256:67a4498b9c68a7068cc2bcfa2d7d5eb35e6ec7e281c0886893f4125a6487c8a1_amd64 as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9-operator@sha256:83c90cf0627a1b99900d539f417e648d8be4c9966452872a93a8236e17b1d1cf_amd64 as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9-operator@sha256:8e1a37dc9fa7b99a65ac9997d49bc9991172a461c63196614d1975bc2210e7fa_ppc64le as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9-operator@sha256:acd2a3adf7365e62689b79608c2289c804f47f97a81f9e8ddf3fecdce6d6f0ec_s390x as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9@sha256:67699f3ec6e1a489b769523d9deaeec57a8113259d375501aa043778828c2286_amd64 as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9@sha256:76f2963c284d0a79e6026bee0837639bce5af84a18c994828aa0890923725189_s390x as a component of Red Hat build of Keycloak 26.0
- rhbk/keycloak-rhel9@sha256:87ff67880fd7f44174b263759c99f4d701cf208eeb6f4abf636a10b98ec023d0_ppc64le as a component of Red Hat build of Keycloak 26.0
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Use the correct TLS configuration and avoid using "--tls-hostname-verifier=any". Workaround: No current mitigations are available for this vulnerability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2025:4335
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2353868
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2358834
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2361923
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_4335.json