Skip to content

Keycloak hostname verification

High
stianst published GHSA-hw58-3793-42gg Apr 30, 2025

Package

maven org.keycloak:keycloak-services (Maven)

Affected versions

< 26.2.2

Patched versions

26.2.2

Description

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

Severity

High

CVE ID

CVE-2025-3501

Weaknesses

No CWEs