PT-2025-32199 · Red Hat · Keycloak

Osidb Bzimport

·

Published

2025-08-06

·

Updated

2025-09-17

·

CVE-2025-8419

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in Keycloak-services where special characters used during email registration may allow SMTP Injection, resulting in the sending of unsolicited emails from the Keycloak server. The attack is limited to short emails (approximately 60 characters) due to the 64-character limit on the local part of the email address. While the direct consequence is limited to sending unwanted emails, this action could potentially be a precursor to more sophisticated attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-09476
CVE-2025-8419
ECHO-891D-8502-3521
GHSA-M4J5-5X4R-2XP9
GHSA-QJ5R-2R5P-PHC7

Affected Products

Keycloak