CVE-2025-11538

A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a remote debugger and achieve remote code execution within the Keycloak Java virtual machine.
Configurations

No configuration.

History

13 Nov 2025, 23:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:21370 -
  • () https://access.redhat.com/errata/RHSA-2025:21371 -

13 Nov 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-13 17:15

Updated : 2025-11-14 16:42


NVD link : CVE-2025-11538

Mitre link : CVE-2025-11538

CVE.ORG link : CVE-2025-11538


JSON object : View

Products Affected

No product.

CWE
CWE-1327

Binding to an Unrestricted IP Address