Junglewise Threat Intelligence

CVE-2025-10939: Keycloak path traversal in admin access via proxy

CVE-2025-10939 · Severity: low · CVSS 3.7 · Published 2025-10-28

Technologies: Keycloak, org.keycloak:keycloak-quarkus-server (Maven). Vendors: Keycloak, Maven.

Executive brief

Keycloak is an open-source identity and access management platform used to secure applications and control user authentication. When deployed behind a proxy (such as HA-Proxy), an attacker can exploit path normalization issues to bypass security controls and access the administrative interface that should not be exposed to the internet, potentially leading to unauthorized administrative access and account compromise.

Technical details

The vulnerability is a path traversal/normalization bypass in Keycloak's handling of the /admin endpoint when deployed behind a proxy. An attacker can craft relative or non-normalized paths (e.g., accessing the admin console via /realms/../admin or similar techniques) that a proxy like HA-Proxy fails to correctly normalize, allowing access to the /admin application path even when it is configured to be restricted. The attack requires network access to the Keycloak instance and exploits the disconnect between how the proxy and Keycloak normalize request paths. The Keycloak project documentation already recommends not exposing the /admin path externally, indicating this is a known architectural concern. A patch is expected from the Keycloak project to address path handling in proxy scenarios.

Affected products

  • Keycloak Keycloak <UNKNOWN>

Timeline

  • 2025-10-28: disclosed

References

Related threats