Insufficient session expiration in Keycloak - CVE-2025-12110
Published: November 17, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise session of other users.
The vulnerability exists due to Keycloak does not invalidate offline sessions when the offline_access scope is removed. The refresh token is accepted and you can continue to request new tokens for the session. A remote authenticated attacker can compromise sessions of other user accounts.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2025-12110
Red Hat build of Keycloak - update to 26.4.4