CVE-2025-10939: Keycloak
Low severity, CVSS 3.7. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relative/non-normalized paths to access the /admin application path relative to /realms which is expected to be exposed.
Affected products
- Keycloak Keycloak: before 26.4.4 (fixed in 26.4.4)
- Red Hat Red Hat Build Of Keycloak 26.4: before 26.4.4-1 (fixed in 26.4.4-1); before 26.4-3 (fixed in 26.4-3)
- Red Hat Red Hat Build Of Keycloak 26.4.4
Published 2025-10-28. Last modified 2026-08-31.