Medium severity5.4OSV Advisory· Published Apr 29, 2025· Updated Sep 21, 2026
CVE-2025-3910
CVE-2025-3910
Description
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | < 26.2.2 | 26.2.2 |
Affected products
10- cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*Range: >=26.0,<26.0.11
- osv-coords8 versionspkg:apk/chainguard/keycloak-bitnami-fipspkg:apk/chainguard/keycloak-fipspkg:apk/chainguard/keycloak-fips-bitnami-compatpkg:apk/chainguard/keycloak-fips-policy-140-2pkg:apk/chainguard/keycloak-fips-policy-140-3pkg:apk/chainguard/keycloak-iamguarded-fipspkg:bitnami/keycloakpkg:maven/org.keycloak/keycloak-services
< 26.2.2-r0+ 7 more
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: >= 26.0.0, < 26.0.11
- (no CPE)range: < 26.2.2
Patches
Vulnerability mechanics
References
8- access.redhat.com/errata/RHSA-2025:4335nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2025:4336nvdVendor AdvisoryWEB
- access.redhat.com/security/cve/CVE-2025-3910nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdVendor AdvisoryWEB
- github.com/advisories/GHSA-5jfq-x6xp-7rw2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-3910ghsaADVISORY
- github.com/keycloak/keycloak/issues/39349nvdIssue TrackingWEB
- github.com/keycloak/keycloak/security/advisories/GHSA-5jfq-x6xp-7rw2ghsaWEB
News mentions
0No linked articles in our index yet.