PT-2025-32199 · Red Hat · Keycloak

·

CVE-2025-8419

·

Published

2025-08-06

·

Updated

2025-09-17

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in Keycloak-services where special characters used during email registration may allow SMTP Injection, resulting in the sending of unsolicited emails from the Keycloak server. The attack is limited to short emails (approximately 60 characters) due to the 64-character limit on the local part of the email address. While the direct consequence is limited to sending unwanted emails, this action could potentially be a precursor to more sophisticated attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09476
CVE-2025-8419
ECHO-891D-8502-3521
GHSA-M4J5-5X4R-2XP9
GHSA-QJ5R-2R5P-PHC7

Affected Products

Keycloak