Memory Management Vulnerability in Okta Java Management SDK
CVE-2025-66033

5.3MEDIUM

Key Information:

Vendor

Okta

Vendor
CVE Published:
10 December 2025

What is CVE-2025-66033?

The Okta Java Management SDK is vulnerable to memory issues stemming from inadequate cleanup of threads after API requests. Affected versions, specifically from 21.0.0 to 24.0.0, may experience performance degradation and availability challenges in long-running applications due to improper handling of multithreaded operations. This could lead to a denial-of-service situation under persistent load, particularly for users utilizing the ApiClient in a multi-threaded environment. To mitigate risks, upgrading to version 24.0.1 is recommended as it addresses these concerns.

Affected Version(s)

okta-sdk-java >= 21.0.0, < 24.0.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-66033 : Memory Management Vulnerability in Okta Java Management SDK