Memory Consumption Vulnerability in Keycloak Identity Management Solution
CVE-2026-101333
3.7LOW
What is CVE-2026-101333?
A vulnerability has been identified in the Micrometer user-event metrics listener of Keycloak. When configured to include the idp tag, it permits an unauthenticated attacker to exploit the identity broker login endpoint with arbitrary provider aliases. This exploitation results in the generation of an unbounded number of metric time series, leading to significant memory exhaustion. Consequently, this poses a risk of performance degradation not only for the Keycloak server but also for associated monitoring tools, potentially affecting the overall system's stability.
References
CVSS V3.1
Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Limzyallin for reporting this issue.