CVE-2025-11537General

LOWCVSS 5.0 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-117

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • General: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-10: 202-10
Signal classification1 categories
General
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2025-11537 A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers in… https://www.cve.org/CVERecord?id=CVE-2025-11537

    Post summary

    The excerpt highlights a Keycloak vulnerability that can leak sensitive headers when verbose logging is enabled, but offers no evidence of exploitation, PoC, or remediation.

    00020699
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-11537 Credential Disclosure in Keycloak Logs When Verbose Logging Patte... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-11537 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet references CVE-2025-11537, noting credential disclosure in Keycloak logs, but provides no proof‑of‑concept, exploit details, patch information, or evidence of active exploitation.

    0000051
    4.0K followersView on X

Explore more