#VU115002 Input validation error in Keycloak - CVE-2025-9162
Published: September 9, 2025 / Updated: November 17, 2025
Keycloak
Keycloak
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input within the keycloak-model-storage-service component. The KeycloakRealmImport custom resource substitutes placeholders within imported realm documents, potentially referencing environment variables. A remote privileged user can inject malicious content during the realm import procedure and gain access to sensitive information.
Remediation
External links
- https://bugzilla.redhat.com/show_bug.cgi?id=2389396
- https://github.com/keycloak/keycloak/blob/75afda410495a9576e00edc3277ab42ca155f806/model/storage-services/src/main/java/org/keycloak/exportimport/AbstractFileBasedImportProvider.java#L35
- https://github.com/advisories/GHSA-w2wj-hw98-233h
- https://github.com/keycloak/keycloak/security/advisories/GHSA-8hxp-qmph-w5gq
- https://github.com/advisories/GHSA-8hxp-qmph-w5gq