Protection mechanism failure in Keycloak - CVE-2025-10939
Published: November 18, 2025 / Updated: December 1, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to the administrative interface.
The vulnerability exists due to incorrect processing of URL paths with certain proxy servers, such as ha-proxy. A remote attacker can force the application into using relative/non-normalized paths to access the /admin application path relative to /realms.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2025-10939
Red Hat build of Keycloak - update to 26.4.4