RHSA-2025:4336HighCVSS 8.2
Red Hat Security Advisory: Red Hat build of Keycloak 26.0.11 Update
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-2559 — org.keycloak/keycloak-services: JWT Token Cache Exhaustion Leading to Denial of Service (DoS) in Keycloak CVE-2025-3501 — org.keycloak.protocol.services: Keycloak hostname verification CVE-2025-3910 — org.keycloak.authentication: Two factor authentication bypass
🎯 Affected products1
- Red Hat Build of Keycloak
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Use the correct TLS configuration and avoid using "--tls-hostname-verifier=any". Workaround: No current mitigations are available for this vulnerability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2025:4336
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2353868
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2358834
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2361923
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_4336.json