Threats Tagged 'cve-2025-10044'
View all threats tagged with 'cve-2025-10044'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-10044'
Click on any threat for detailed analysis and mitigation recommendations
A moderate severity vulnerability (CVE-2025-10044) affects Red Hat build of Keycloak 26.0.17, involving error_description injection on error pages. This vulnerability relates to improper handling of error messages that could lead to injection issues. Red Hat has issued an advisory for this vulnerability but has not explicitly stated a patch availability or fixed version. Users are advised to back up their installations before applying updates. No known exploits are reported in the wild. Join the discussion | GCVE Database | 11/07/2025, 12:03:36 UTC Added: 08/31/2026, 15:42:59 UTC |
Red Hat has released a security update for its build of Keycloak 26.2.9 addressing three vulnerabilities: variable injection into environment variables (CVE-2025-9162), an incomplete fix of a previous vulnerability (CVE-2024-10492) resulting in CVE-2025-10043, and error_description injection on error pages (CVE-2025-10044). These issues affect the authentication and single sign-on capabilities provided by Keycloak. The update is classified as moderate severity. Join the discussion | GCVE Database | 09/22/2025, 15:36:01 UTC Added: 06/28/2026, 22:14:12 UTC |
Red Hat has released a security update for the Red Hat build of Keycloak 26.2.9 images used within OpenShift Container Platform. The update addresses three security issues: variable injection into environment variables (CVE-2025-9162), an incomplete fix of a previous vulnerability (CVE-2024-10492) now tracked as CVE-2025-10043, and error_description injection on error pages (CVE-2025-10044). These issues could potentially allow injection attacks affecting authentication and error handling components. The update is provided as new container images aligning with the standalone Keycloak 26.2.9 release. Users are advised to back up their existing installations before applying the update. Join the discussion | GCVE Database | 09/22/2025, 15:35:49 UTC Added: 06/28/2026, 22:14:12 UTC |
A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in the error_description query parameter. This text is directly rendered in error pages without validation or sanitization. While HTML encoding prevents XSS, an attacker can craft URLs with misleading messages (e.g., fake support phone numbers or URLs), which are displayed within the trusted Keycloak UI. This creates a phishing vector, potentially tricking users into contacting malicious actors. Join the discussion | CVE Database V5 | 09/05/2025, 19:59:04 UTC Added: 09/05/2025, 20:04:47 UTC |
Showing 1 to 4 of 4 results