Race Condition Vulnerability in Okta Java Management SDK
CVE-2025-67505

8.4HIGH

Key Information:

Vendor

Okta

Vendor
CVE Published:
10 December 2025

What is CVE-2025-67505?

The Okta Java Management SDK, which is used for interacting with the Okta management API, is subject to a race condition issue. In versions 11.0.0 through 20.0.0, if multiple requests are made simultaneously via the ApiClient class, there is a risk that one request’s status code or response header could improperly influence another request's response. This behavior presents potential inconsistencies in API response handling. The issue was addressed in version 20.0.1, which mitigates these concerns and enhances overall API interaction reliability.

Affected Version(s)

okta-sdk-java >= 11.0.0, < 20.0.1

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-67505 : Race Condition Vulnerability in Okta Java Management SDK