Medium severity5.4GHSA Advisory· Published Oct 23, 2025· Updated Apr 15, 2026
CVE-2025-12110
CVE-2025-12110
Description
A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the client. The refresh token is accepted and you can continue to request new tokens for the session. As it can lead to a situation where an administrator removes the scope, and assumes that offline sessions are no longer available, but they are.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | < 26.2.3 | 26.2.3 |
Affected products
3- osv-coords2 versions
< 26.2.5-r6+ 1 more
- (no CPE)range: < 26.2.5-r6
- (no CPE)range: < 26.2.3
Patches
Vulnerability mechanics
References
11- github.com/advisories/GHSA-895x-rfqp-jh5cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-12110ghsaADVISORY
- access.redhat.com/errata/RHSA-2025:21370nvdWEB
- access.redhat.com/errata/RHSA-2025:21371nvdWEB
- access.redhat.com/errata/RHSA-2025:22088nvdWEB
- access.redhat.com/errata/RHSA-2025:22089nvdWEB
- access.redhat.com/security/cve/CVE-2025-12110nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/keycloak/keycloak/commit/54e1c8af1e089ad33d32e0f2792610e4b8df421bghsaWEB
- github.com/keycloak/keycloak/commit/c830a27928cac4294619af7d147bdff34d4a85e7ghsaWEB
- github.com/keycloak/keycloak/pull/43790nvdWEB
News mentions
0No linked articles in our index yet.