A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

Project Subscriptions

Vendors Products
Build Keycloak Subscribe
Red Hat Single Sign On Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2025-12660 A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.
Github GHSA Github GHSA GHSA-hw58-3793-42gg Keycloak hostname verification
Fixes

Solution

No solution given by the vendor.


Workaround

Use the correct TLS configuration and avoid using "--tls-hostname-verifier=any".

History

Thu, 07 Aug 2025 12:30:00 +0000


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00029}

epss

{'score': 0.00012}


Mon, 09 Jun 2025 14:00:00 +0000

Type Values Removed Values Added
References

Mon, 09 Jun 2025 13:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak:26.2::el9
References

Fri, 02 May 2025 02:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 30 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Apr 2025 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak:26
References

Tue, 29 Apr 2025 23:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak: cpe:/a:redhat:build_keycloak:26.0::el9
References

Tue, 29 Apr 2025 21:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.
Title Org.keycloak.protocol.services: keycloak hostname verification
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-297
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-11-20T07:27:01.176Z

Reserved: 2025-04-10T12:29:29.427Z

Link: CVE-2025-3501

cve-icon Vulnrichment

Updated: 2025-04-30T15:54:18.202Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-29T21:15:51.523

Modified: 2025-08-07T13:15:36.340

Link: CVE-2025-3501

cve-icon Redhat

Severity : Important

Publid Date: 2025-04-29T00:00:00Z

Links: CVE-2025-3501 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses