๐Ÿ” CVE Alert

CVE-2025-11429

MEDIUM 5.4

Keycloak-server: too long and not settings compliant session

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on existing user sessions. Sessions created while "Remember Me" was active retain their extended session lifetime until they expire, overriding the administrator's recent security configuration change. This is a logic flaw in session management increases the potential window for successful session hijacking or unauthorized long-term access persistence. The flaw lies in the session expiration logic relying on the session-local "remember-me" flag without validating the current realm-level configuration.

CWE CWE-613
Vendor keycloak
Product keycloak
Published Oct 23, 2025
Last Updated Jan 20, 2026
Stay Ahead of the Next One

Get instant alerts for keycloak keycloak

Be the first to know when new medium vulnerabilities affecting keycloak keycloak are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Keycloak / keycloak
0 < 26.4.1
Red Hat / Red Hat build of Keycloak 26.2
All versions affected
Red Hat / Red Hat build of Keycloak 26.2
All versions affected
Red Hat / Red Hat build of Keycloak 26.2
All versions affected
Red Hat / Red Hat build of Keycloak 26.2.11
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2025:22088 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:22089 access.redhat.com: https://access.redhat.com/security/cve/CVE-2025-11429 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2402148 github.com: https://github.com/keycloak/keycloak/commit/a34094100716b7c69ae38eaed6678ab4344d0a1d github.com: https://github.com/keycloak/keycloak/commit/bda0e2a67c8cf41d1b3d9010e6dfcddaf79bf59b github.com: https://github.com/keycloak/keycloak/issues/43328

Credits

This issue was discovered by Alexander Schwartz (Red Hat).