CVE 5.5 MEDIUM

Org.keycloak.storage.ldap: keycloak: deserialization of untrusted data in ldap user federation_CVE-2025-13467

5.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

Description

A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.

Basic Information

ID CVE-2025-13467
Source redhat
Published Nov 25, 2025 at 16:02
Modified Nov 25, 2025 at 21:30

Affected Product

Vendor Red Hat
Product Red Hat build of Keycloak 26.2
Version 26.2.11-1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.