PT-2025-46862 · Red Hat · Keycloak

Steven Hawkins

·

Published

2025-11-13

·

Updated

2025-12-01

·

CVE-2025-11538

CVSS v3.1

6.8

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A security issue exists in Keycloak where enabling debug mode with the --debug flag insecurely binds the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0). This exposes the debug port to the local network, potentially allowing a malicious actor on the same network segment to attach a remote debugger and execute code remotely within the Keycloak Java virtual machine. The vulnerable parameter is <port>.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-11538
GHSA-7M9G-PMXF-M9M8
GHSA-J4VQ-Q93M-4683

Affected Products

Keycloak