PT-2025-44075 · Red Hat · Keycloak

·

CVE-2025-11419

·

Published

2025-10-27

·

Updated

2026-02-13

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description Keycloak is susceptible to a Denial of Service (DoS) attack. This is due to a default Java Development Kit (JDK) setting that allows Client-Initiated Renegotiation within the TLS 1.2 protocol. An attacker who does not need to be authenticated can send repeated TLS renegotiation requests. This can overwhelm the server's CPU, leading to service unavailability.
Recommendations Set the -Djdk.tls.rejectClientInitiatedRenegotiation=true Java system property in the Keycloak startup configuration.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11419
GHSA-Q8HQ-4H99-FJ7X

Affected Products

Keycloak