CVE Database
/

CVE-2025-10044

Back to search

CVE-2025-10044

Published: Sep 5, 2025

Modified: Dec 19, 2025

PUBLISHED

CVSS v3.1

4.3

MEDIUM

Description

A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in the error_description query parameter. This text is directly rendered in error pages without validation or sanitization. While HTML encoding prevents XSS, an attacker can craft URLs with misleading messages (e.g., fake support phone numbers or URLs), which are displayed within the trusted Keycloak UI. This creates a phishing vector, potentially tricking users into contacting malicious actors.

VendorProductVersions

Keycloak

keycloak

affected
0 - < 26.2.9

Red Hat

Red Hat build of Keycloak 26.0

unaffected
26.0.17-1 - < *

Red Hat

Red Hat build of Keycloak 26.0

unaffected
26.0-21 - < *

Red Hat

Red Hat build of Keycloak 26.0

unaffected
26.0-22 - < *

Red Hat

Red Hat build of Keycloak 26.0.17

All versions

Red Hat

Red Hat build of Keycloak 26.2

unaffected
26.2.9-1 - < *

Red Hat

Red Hat build of Keycloak 26.2

unaffected
26.2-9 - < *

Red Hat

Red Hat build of Keycloak 26.2

unaffected
26.2-9 - < *

Red Hat

Red Hat build of Keycloak 26.2.9

All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

None

References

RHSA-2025:16399
vendor-advisory
x_refsource_REDHAT
RHSA-2025:16400
vendor-advisory
x_refsource_REDHAT
RHSA-2025:19923
vendor-advisory
x_refsource_REDHAT
RHSA-2025:19925
vendor-advisory
x_refsource_REDHAT
RHBZ#2393551
issue-tracking
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now