Protection mechanism failure in Keycloak - CVE-2025-10939
Published: November 18, 2025 / Updated: December 1, 2025
Keycloak
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to the administrative interface.
The vulnerability exists due to incorrect processing of URL paths with certain proxy servers, such as ha-proxy. A remote attacker can force the application into using relative/non-normalized paths to access the /admin application path relative to /realms.