RHSA-2025:4336HighCVSS 8.2

Red Hat Security Advisory: Red Hat build of Keycloak 26.0.11 Update

Published
April 29, 2025
Last Modified
September 21, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2025-2559 — org.keycloak/keycloak-services: JWT Token Cache Exhaustion Leading to Denial of Service (DoS) in Keycloak CVE-2025-3501 — org.keycloak.protocol.services: Keycloak hostname verification CVE-2025-3910 — org.keycloak.authentication: Two factor authentication bypass

🎯 Affected products1

  • Red Hat Build of Keycloak

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Use the correct TLS configuration and avoid using "--tls-hostname-verifier=any". Workaround: No current mitigations are available for this vulnerability.

🔗 References (6)