#VU118800 Deserialization of Untrusted Data in Keycloak - CVE-2025-13467
Published: November 27, 2025 / Updated: December 19, 2025
Keycloak
Keycloak
Description
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to insecure input validation when processing serialized data in the Keycloak LDAP User Federation provider. A remote privileged user can create a malicious LDAP server configuration and execute arbitrary code on the target system.