Skip to main content

Threats Tagged 'cve-2025-12150'

View all threats tagged with 'cve-2025-12150'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-12150

Threats Tagged 'cve-2025-12150'

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability in Keycloak's WebAuthn registration component allows bypassing the configured attestation policy by submitting an attestation object with fmt: "none". This occurs even when the realm requires direct attestation, potentially enabling registration of untrusted or forged authenticators. The issue affects Keycloak versions prior to 26.4.4. A security update is available from Red Hat to address this flaw.

Join the discussion

A security update for Red Hat build of Keycloak 26.2.11 addresses a vulnerability involving deserialization of untrusted data in LDAP User Federation (CVE-2025-13467). This issue affects containerized images used within the OpenShift Container Platform for on-premise or private cloud deployments. The update provides new images aligning with the standalone product release to mitigate this moderate severity vulnerability.

Join the discussion

Red Hat has issued a security update for its build of Keycloak version 26.2.11 addressing a moderate severity vulnerability involving deserialization of untrusted data in the LDAP User Federation component (CVE-2025-13467). This vulnerability could potentially allow an attacker to exploit unsafe deserialization processes. The advisory recommends backing up existing installations before applying the update. No explicit patch link is provided in the advisory, and no known exploits are reported in the wild.

Join the discussion

Red Hat has released security updates for the Red Hat build of Keycloak 26.4.4 images used within OpenShift Container Platform. The update addresses multiple vulnerabilities including improper access restriction to the admin console, debug bind address exposure, offline session refresh issues, WebAuthn attestation verification bypass, and offline session takeover due to reused authentication session IDs. These issues affect the authentication server functionality used for centralized login and user management in containerized environments.

Join the discussion

Red Hat has issued a security update for its build of Keycloak version 26.4.4 addressing multiple moderate severity vulnerabilities. These include issues such as inability to restrict access to the admin console, debug bind address exposure, offline session refresh after scope removal, WebAuthn attestation bypass, and offline session takeover due to reused authentication session IDs. The update is intended to fix these security flaws to improve the authentication server's security posture.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cve-2025-12150
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses