CVE-2025-11419: Red Hat Build Of Keycloak 26.0

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A flaw was found in Keycloak. This vulnerability allows an unauthenticated remote attacker to cause a denial of service (DoS) by repeatedly initiating TLS 1.2 client-initiated renegotiation requests to exhaust server CPU resources, making the service unavailable.

Affected products

  • Red Hat Red Hat Build Of Keycloak 26.0: before 26.0.16-2 (fixed in 26.0.16-2); before 26.0-20 (fixed in 26.0-20); before 26.0-21 (fixed in 26.0-21)
  • Red Hat Red Hat Build Of Keycloak 26.0.16
  • Red Hat Red Hat Build Of Keycloak 26.2: before 26.2.10-2 (fixed in 26.2.10-2); before 26.2-11 (fixed in 26.2-11)
  • Red Hat Red Hat Build Of Keycloak 26.2.10

Published 2025-12-23. Last modified 2026-06-17.