Configuration in Keycloak - CVE-2025-11538
Published: November 18, 2025 / Updated: December 1, 2025
Vulnerability details
The issue may allow a remote attacker to gain unauthorized access to the application.
The issue exists due to insecure default configuration of the server with enabled debug mode. The server binds by default the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0), exposing the interface to remote attackers.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2025-11538
Red Hat build of Keycloak - update to 26.4.4