CVE-2025-8419
Keycloak SMTP Inject Vulnerability
5.3
MEDIUM
CVSS 3.1
EPSS 0.11%
Description
Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send short unwanted e-mails. The email is limited to 64 characters (limited local part of the email), so the attack is limited to very shorts emails (subject and little data, the example is 60 chars). This flaw's only direct consequence is an unsolicited email being sent from the Keycloak server. However, this action could be a precursor for more sophisticated attacks.
How to fix CVE-2025-8419
To remediate CVE-2025-8419, upgrade the affected package to a fixed version below.
- —upgrade to 26.2.8 or later
Is CVE-2025-8419 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 26.2.8
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |