RHSA-2025:2545MediumCVSS 7.5

Red Hat Security Advisory: Red Hat build of Keycloak 26.0.10 Update

Published
March 10, 2025
Last Modified
July 22, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2024-47072 — com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream CVE-2025-0604 — keycloak-ldap-federation: Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak CVE-2025-1391 — keycloak-services: Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims

🔗 References (5)