Deserialization Vulnerability in Keycloak LDAP User Federation Provider
CVE-2025-13467
Key Information:
- Vendor
Keycloak
- Status
- Vendor
- CVE Published:
- 25 November 2025
What is CVE-2025-13467?
A vulnerability has been identified in the Keycloak LDAP User Federation provider that allows an authenticated realm administrator to inadvertently trigger the deserialization of untrusted Java objects through a malicious configuration of an LDAP server. This flaw potentially exposes the system to various forms of attacks, emphasizing the importance for administrators to apply security patches and review configurations to mitigate the risks associated with unauthorized access and data manipulation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Keycloak 0 < 26.4.6
Red Hat build of Keycloak 26.2 26.2.11-1
Red Hat build of Keycloak 26.2 26.2-12
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
