High severity8.2GHSA Advisory· Published Apr 29, 2025· Updated Apr 15, 2026
CVE-2025-3501
CVE-2025-3501
Description
A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | < 26.2.2 | 26.2.2 |
Affected products
8- osv-coords7 versionspkg:apk/chainguard/keycloak-bitnami-fipspkg:apk/chainguard/keycloak-fipspkg:apk/chainguard/keycloak-fips-bitnami-compatpkg:apk/chainguard/keycloak-fips-policy-140-2pkg:apk/chainguard/keycloak-fips-policy-140-3pkg:apk/chainguard/keycloak-iamguarded-fipspkg:maven/org.keycloak/keycloak-services
< 26.2.2-r0+ 6 more
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2
Patches
Vulnerability mechanics
References
12- github.com/advisories/GHSA-hw58-3793-42ggghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-3501ghsaADVISORY
- access.redhat.com/errata/RHSA-2025:4335nvdWEB
- access.redhat.com/errata/RHSA-2025:4336nvdWEB
- access.redhat.com/security/cve/CVE-2025-3501nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/keycloak/keycloak/commit/99ca24c832729075e04d8bc58666089268314272ghsaWEB
- github.com/keycloak/keycloak/issues/39350nvdWEB
- github.com/keycloak/keycloak/pull/39366nvdWEB
- github.com/keycloak/keycloak/security/advisories/GHSA-hw58-3793-42ggghsaWEB
- access.redhat.com/errata/RHSA-2025:8672nvd
- access.redhat.com/errata/RHSA-2025:8690nvd
News mentions
0No linked articles in our index yet.