CVE-2025-11537
Keycloak logs sensitive headers
Description
A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise. Patches are available, see: - https://github.com/keycloak/keycloak/releases/tag/26.4.11 - https://github.com/keycloak/keycloak/releases/tag/26.5.6 - https://github.com/keycloak/keycloak/releases/tag/26.6.0
How to fix CVE-2025-11537
To remediate CVE-2025-11537, upgrade the affected package to a fixed version below.
- —upgrade to 26.5.6 or later
Is CVE-2025-11537 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 26.5.6
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.0 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |