CVE-2025-3501: Red Hat Build Of Keycloak

High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

Affected products

  • Red Hat Red Hat Build Of Keycloak
  • Red Hat Red Hat Build Of Keycloak 26
  • Red Hat Red Hat Build Of Keycloak 26.0: before 26.0.11-2 (fixed in 26.0.11-2); before 26.0-12 (fixed in 26.0-12); before 26.0-13 (fixed in 26.0-13)
  • Red Hat Red Hat Build Of Keycloak 26.2: before 26.2.5-1 (fixed in 26.2.5-1); before 26.2-4 (fixed in 26.2-4)
  • Red Hat Red Hat Single Sign-On 7

Published 2025-04-29. Last modified 2026-09-21.