# CVE-2025-3501

## Summary

- **CVE ID:** CVE-2025-3501
- **Severity:** HIGH
- **CVSS Score:** 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N)
- **CWE:** CWE-297
- **Published:** Apr 29, 2025
- **Last Modified:** Mar 12, 2026

## Description

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

## Affected Products

- Unknown product (25.0.0)
- Unknown product (26.0.0)
- Unknown product (26.1.0)
- Unknown product (26.2.0)
- Red Hat — Red Hat build of Keycloak 26.0 (26.0.11-2)
- Red Hat — Red Hat build of Keycloak 26.0 (26.0-12)
- Red Hat — Red Hat build of Keycloak 26.0 (26.0-13)
- Red Hat — Red Hat build of Keycloak 26.2 (26.2.5-1)
- Red Hat — Red Hat build of Keycloak 26.2 (26.2-4)

## References

- [CNA](https://access.redhat.com/errata/RHSA-2025:4335)
- [CNA](https://access.redhat.com/errata/RHSA-2025:4336)
- [CNA](https://access.redhat.com/errata/RHSA-2025:8672)
- [CNA](https://access.redhat.com/errata/RHSA-2025:8690)
- [CNA](https://access.redhat.com/security/cve/CVE-2025-3501)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2358834)
- [CNA](https://github.com/keycloak/keycloak/issues/39350)
- [CNA](https://github.com/keycloak/keycloak/pull/39366)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.44%
- **EPSS Percentile:** 37.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._