ECHO-1ec0-58d1-cb3d

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-1ec0-58d1-cb3d.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-1ec0-58d1-cb3d
Upstream
  • CVE-2025-11537
Withdrawn
2026-08-31T14:30:19Z
Published
2026-08-30T16:45:31Z
Modified
2026-08-31T15:15:04Z
Summary
Keycloak's GHSA advisory (GHSA-gv3v-2cpp-3pmq) lists the affected package/range as org.keycloak:keycloak-quarkus-server < 26.5.6 with no lower bound, so by version string alone 25.0.6 is nominally in range. The actual vulnerable mechanism is the HTTP access log feature (config.HttpAccessLogOptions, HttpAccessLogPropertyMappers) added by the fix commit's PR to mask Authorization/Cookie headers in a verbose access-log pattern. That feature does not exist in 25.0.6 at all — confirmed via a full source search (no HttpAccessLogOptions.java, HttpAccessLogPropertyMappers.java, or any http-access-log config option anywhere in quarkus/config-api or quarkus/runtime). There is no access-log-pattern mechanism in this version capable of the described header disclosure.
Details
References

Affected packages

Echo / keycloak-25

Package

Name
keycloak-25
Purl
pkg:deb/echo/keycloak-25

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
25.0.6+e2

Database specific

source
"https://advisory.echohq.com/osv/ECHO-1ec0-58d1-cb3d.json"

Echo:Maven / org.keycloak:keycloak-quarkus-server

Package

Name
org.keycloak:keycloak-quarkus-server
Purl
pkg:maven/org.keycloak/keycloak-quarkus-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

source
"https://advisory.echohq.com/osv/ECHO-1ec0-58d1-cb3d.json"