Medium severity5.4OSV Advisory· Published Apr 29, 2025· Updated Jun 17, 2026
CVE-2025-3910
CVE-2025-3910
Description
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | < 26.2.2 | 26.2.2 |
Affected products
9- ghsa-coords7 versionspkg:maven/org.keycloak/keycloak-servicespkg:apk/chainguard/keycloak-fips-policy-140-3pkg:apk/chainguard/keycloak-bitnami-fipspkg:apk/chainguard/keycloak-fipspkg:apk/chainguard/keycloak-fips-bitnami-compatpkg:apk/chainguard/keycloak-fips-policy-140-2pkg:apk/chainguard/keycloak-iamguarded-fips
< 26.2.2+ 6 more
- (no CPE)range: < 26.2.2
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- (no CPE)range: < 26.2.2-r0
- cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:text-only:*:*:*Range: >=26.0,<26.0.11
Patches
Vulnerability mechanics
References
8- access.redhat.com/errata/RHSA-2025:4335nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2025:4336nvdVendor AdvisoryWEB
- access.redhat.com/security/cve/CVE-2025-3910nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdVendor AdvisoryWEB
- github.com/advisories/GHSA-5jfq-x6xp-7rw2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-3910ghsaADVISORY
- github.com/keycloak/keycloak/issues/39349nvdIssue TrackingWEB
- github.com/keycloak/keycloak/security/advisories/GHSA-5jfq-x6xp-7rw2ghsaWEB
News mentions
0No linked articles in our index yet.