Deserialization of Untrusted Data in Keycloak - CVE-2025-13467
Published: November 27, 2025 / Updated: December 19, 2025
Vulnerability details
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to insecure input validation when processing serialized data in the Keycloak LDAP User Federation provider. A remote privileged user can create a malicious LDAP server configuration and execute arbitrary code on the target system.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2025-13467
Red Hat build of Keycloak - addressed in versions 26.2.11, 26.4.6