RHSA-2025:8672HighCVSS 8.2

Red Hat Security Advisory: Red Hat build of Keycloak 26.2.5 Images Security Update

Published
June 9, 2025
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-47072 — com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream CVE-2025-3501 — org.keycloak.protocol.services: Keycloak hostname verification

🎯 Affected products10

  • Red Hat build of Keycloak 26.2
  • rhbk/keycloak-operator-bundle@sha256:4ecfe1e2059cc2d7087e01ae04598bd5628f2958c21e14e41fa249dccf0d3e5f_amd64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:2a85cb76b1d5cd7cf2a8b0d809249470b049ae5b8de32186ceac4ae13e7758e3_ppc64le as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:2cb97ec2a8ac79b31a678d348b2217e008d39b1f8482e75c1baf8acc026910c1_s390x as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:35d37a09fa0a9799258aede346e1cb205179617ab2e417c809e18dee2ed1860a_amd64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9-operator@sha256:c9d86fff34b796441318e5fd211b69f07b4aaacfd49f7d2b02d972329cb61d83_arm64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:55062a4e89ec53f2759aeb7fe5f117a658e182ee898a78074f47330943ff14eb_s390x as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:b87e36a465c9a84edc7b74ac46ca555cd5189731eaeec9da7f05f1e41cc86e70_arm64 as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:e24acc11a1bc60321cec78a5f2bc2521636fe00fddd9e742d7b25131f3152c5a_ppc64le as a component of Red Hat build of Keycloak 26.2
  • rhbk/keycloak-rhel9@sha256:e3e211f233016ade5c98aa16f979d97a90c8af369bc81cd526e2a40e53ed4daa_amd64 as a component of Red Hat build of Keycloak 26.2

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Use the correct TLS configuration and avoid using "--tls-hostname-verifier=any".

🔗 References (3)