{"id":"CVE-2025-11538","aliases":["GHSA-j4vq-q93m-4683"],"url":"https://o3.security/vulnerability/CVE-2025-11538","summary":"Keycloak-server: debug default bind address","details":"A vulnerability exists in Keycloak's server distribution where enabling debug mode (`--debug`) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (`0.0.0.0`). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a remote debugger and achieve remote code execution within the Keycloak Java virtual machine.\n\nRed Hat evaluates this as a Moderate impact vulnerability due to the requirement of running debug mode and untrusted network. Also, for Red Hat Single Sign-On, this must as well be bound to 0.0.0.0 address, which is not recommended in production scenarios.","published":"2025-11-13T16:47:53.933Z","modified":"2026-08-12T03:51:16.288886216Z","cvss":{"score":6.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":{"score":0.00393,"percentile":0.3306,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.keycloak:keycloak-quarkus-dist","fixedVersion":"26.4.4"}],"fix":{"url":"https://github.com/keycloak/keycloak/commit/9e98f2bf961f68853cea6fbec58b512ed8be7ca9","label":"keycloak/keycloak@9e98f2b"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://catalog.redhat.com/software/containers/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:21370"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:21371"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-11538"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11538.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11538"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2402622"},{"type":"FIX","url":"https://github.com/keycloak/keycloak/commit/9e98f2bf961f68853cea6fbec58b512ed8be7ca9"},{"type":"FIX","url":"https://github.com/keycloak/keycloak/pull/43574"},{"type":"PACKAGE","url":"https://github.com/keycloak/keycloak"},{"type":"WEB","url":"https://github.com/keycloak/keycloak/security/advisories/GHSA-j4vq-q93m-4683"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:16.288886216Z"}}