<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 06:37:31 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-11538 — Keycloak-server: debug default bind address</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-11538</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; keycloak, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.4&lt;/p&gt;
&lt;p&gt;A vulnerability exists in Keycloak&amp;#39;s server distribution where enabling debug mode (--debug &amp;lt;port&amp;gt;) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a remote debugger and achieve remote code execution within the Keycloak Java virtual machine.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; keycloak, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.4&lt;/p&gt;
&lt;p&gt;A vulnerability exists in Keycloak&amp;#39;s server distribution where enabling debug mode (--debug &amp;lt;port&amp;gt;) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a remote debugger and achieve remote code execution within the Keycloak Java virtual machine.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-11538</guid>
    </item>
  </channel>
</rss>
