CVE-2025-13467: Keycloak

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.

Affected products

  • Keycloak Keycloak: before 26.4.6 (fixed in 26.4.6)
  • Red Hat Red Hat Build Of Keycloak 26.2: before 26.2.11-1 (fixed in 26.2.11-1); before 26.2-12 (fixed in 26.2-12)
  • Red Hat Red Hat Build Of Keycloak 26.2.11
  • Red Hat Red Hat Build Of Keycloak 26.4: before 26.4.6-1 (fixed in 26.4.6-1); before 26.4-6 (fixed in 26.4-6); before 26.4-5 (fixed in 26.4-5)
  • Red Hat Red Hat Build Of Keycloak 26.4.6

Published 2025-11-25. Last modified 2026-06-17.