MEDIUMMaven →
Keycloak does not invalidate sessions when "Remember Me" is disabled
Keycloak does not invalidate sessions when "Remember Me" is disabled
Affected packages
- org.keycloak:keycloak-services— 26.3.0 → 26.4.1
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2025-11429
- https://github.com/keycloak/keycloak/issues/43328
- https://github.com/keycloak/keycloak/commit/a34094100716b7c69ae38eaed6678ab4344d0a1d
- https://github.com/keycloak/keycloak/commit/a752492843e21c3ab06090616692e53001864158
- https://github.com/keycloak/keycloak/commit/bda0e2a67c8cf41d1b3d9010e6dfcddaf79bf59b
- https://access.redhat.com/errata/RHSA-2025:22088
- https://access.redhat.com/errata/RHSA-2025:22089
- https://access.redhat.com/security/cve/CVE-2025-11429
- https://bugzilla.redhat.com/show_bug.cgi?id=2402148
- https://github.com/keycloak/keycloak
Structured record: https://osv.dev/vulnerability/GHSA-64w3-5q9m-68xf
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta