CVE-2025-12150 - Org.keycloak/keycloak-services: webauthn attestation statement verification bypass

CVE-2025-12150 - Org.keycloak/keycloak-services: webauthn attestation statement verification bypass

CVE ID : CVE-2025-12150 Published : Feb. 27, 2026, 9:16 a.m. | 1 hour, 7 minutes ago Description : A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt:

CVE Details

Published
Feb. 27, 2026