<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 10:36:51 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-12150 — Org.keycloak/keycloak-services: webauthn attestation statement verification bypass</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-12150</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; keycloak, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.11, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.4&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: &amp;#34;none&amp;#34;, even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; keycloak, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.11, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.4&lt;/p&gt;
&lt;p&gt;A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: &amp;#34;none&amp;#34;, even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-12150</guid>
    </item>
  </channel>
</rss>
