RHSA-2025:0299MediumCVSS 6.5

Red Hat Security Advisory: Red Hat build of Keycloak 26.0.8 Images Update

Published
January 13, 2025
Last Modified
August 31, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2024-11734 — org.keycloak:keycloak-quarkus-server: Denial of Service in Keycloak Server via Security Headers CVE-2024-11736 — org.keycloak:keycloak-quarkus-server: Unrestricted admin use of system and environment variables

🎯 Affected products8

  • Red Hat build of Keycloak 26.0
  • rhbk/keycloak-operator-bundle@sha256:7e01d2b84d68279d7fb7bae6318a8460cf966a25c4eb68a1bdbf9819d0407151_amd64 as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9-operator@sha256:48e0529d9e86b9b9599312c9cceb6ca6aea34955c08a944f81e716cd1c656873_s390x as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9-operator@sha256:8846f0ce0c6efdd25df17864ae0d9c2979471eba31e363d32a4edc3db9280a81_ppc64le as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9-operator@sha256:e5ffa9b04609ec7678762da51bbaf987efbbd70ef26010f08f29b145bc2669f6_amd64 as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9@sha256:43c9af1192b7862d5f4f090bbeb4d060b8b4c58379074a0837e56340821f2eca_s390x as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9@sha256:7d17092fee39df78518829f19d5d3d2796046bd1c8c305eb98296a4a8409cc76_amd64 as a component of Red Hat build of Keycloak 26.0
  • rhbk/keycloak-rhel9@sha256:dba38571032de9a02182f99ef85ee2512a9112f60622905e3e6044bbf57d3012_ppc64le as a component of Red Hat build of Keycloak 26.0

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (5)