PT-2025-44075 · Red Hat · Keycloak
Osidb Bzimport
·
Published
2025-10-27
·
Updated
2026-02-13
·
CVE-2025-11419
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Keycloak (affected versions not specified)
Description
Keycloak is susceptible to a Denial of Service (DoS) attack. This is due to a default Java Development Kit (JDK) setting that allows Client-Initiated Renegotiation within the TLS 1.2 protocol. An attacker who does not need to be authenticated can send repeated TLS renegotiation requests. This can overwhelm the server's CPU, leading to service unavailability.
Recommendations
Set the
-Djdk.tls.rejectClientInitiatedRenegotiation=true Java system property in the Keycloak startup configuration.Fix
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keycloak