CVE-2025-3501
A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- EPSS probability
- 0.44%
- CWE
- CWE-297
- Published
- 2025-04-29
- Last modified
- 2026-03-12
Affected products
- Red Hat Red Hat build of Keycloak 26.0
- Red Hat Red Hat build of Keycloak 26.0
- Red Hat Red Hat build of Keycloak 26.0
- Red Hat Red Hat build of Keycloak 26.2
- Red Hat Red Hat build of Keycloak 26.2
Weakness type
Related vulnerabilities
- CVE-2020-11050 — Improper Validation of Certificate with Host Mismatch in Java-WebSocket
- CVE-2021-21385 — Disabled hostname verification and accepting self-signed certificates
- CVE-2018-10936 — A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check t
- CVE-2022-32153 — Splunk Enterprise lacked TLS host name validation
- CVE-2026-59638 — JSSE hostname verifier CN-fallback enabled by default despite documented opt-in
- CVE-2026-84197 — In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from
- CVE-2026-15925 — Improper TLS Hostname Verification in Snowflake Connector for Python
- CVE-2026-26214 — Xiaomi Galaxy FDS Android SDK <= 3.0.8 TLS Hostname Verification Disabled Enables MITM