# PingFederate 2025 advisory

Source: https://startwithidentity.com/cves/cve-2025-21085/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

CVE-2025-21085 is a [PingFederate](https://startwithidentity.com/vendors/iam/ping-identity/) issue assigned in 2025. Public NVD enrichment was limited when this catalog was compiled. Ping has a long history of federation-plane bugs (client_secret_jwt auth bypass on 11.3, Identifier First Adapter, PingID offline MFA). Do not wait for a perfect NVD page.

## Why it matters

PingFederate is an [IdP](https://startwithidentity.com/glossary/identity-provider/) and an [OAuth](https://startwithidentity.com/glossary/oauth/) authorization server for a large share of workforce and customer federation. An unpatched PF node is an identity incident waiting on a write-up.

## What to do

- Read the Ping advisory that names CVE-2025-21085 and install the build it lists.
- If NVD is still empty, the vendor page is the source of truth. That is the 2026 enrichment reality, not a reason to stall.

## After you patch

Token-layer flaws produce credentials that keep working after the patch, so remediation is about invalidating what was issued.

- **Rotate the signing keys** published at your [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint, then confirm relying parties refetch on an unknown key id rather than caching indefinitely.
- **Revoke [refresh tokens](https://startwithidentity.com/glossary/refresh-token/) and sessions.** Access tokens expire on their own; refresh tokens are the ones that turn a short compromise into months of access.
- **Audit client registrations and consent grants** created during the window, particularly any client with broad scopes or a redirect URI you do not recognize.
- **Verify validation on your side**: pinned algorithms, issuer and audience checks, and no acceptance of `alg: none`. See [JWT](https://startwithidentity.com/glossary/jwt/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).

## Sources

- [NVD: CVE-2025-21085](https://nvd.nist.gov/vuln/detail/CVE-2025-21085)
- Ping Identity support advisories
