A flaw was found in Keycloak. This vulnerability allows an unauthenticated remote attacker to cause a denial of service (DoS) by repeatedly initiating TLS 1.2 client-initiated renegotiation requests to exhaust server CPU resources, making the service unavailable.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11419.json",
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-770"
]
}{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "26.0.16"
},
{
"introduced": "26.2.0"
},
{
"fixed": "26.2.10"
},
{
"introduced": "26.4.0"
},
{
"fixed": "26.4.1"
}
]
}