Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat build Of Keycloak
Redhat single Sign-on |
|
| Vendors & Products |
Redhat build Of Keycloak
Redhat single Sign-on |
Mon, 28 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider aliases, causing the system to create an unlimited number of metric time series. This can lead to excessive memory consumption and degrade the performance of both the server and its monitoring tools. | |
| Title | Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on broker login endpoint | |
| First Time appeared |
Redhat
Redhat build Keycloak Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:/a:redhat:build_keycloak: cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat build Keycloak Redhat red Hat Single Sign On |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-28T15:18:21.493Z
Reserved: 2026-09-28T14:09:11.117Z
Link: CVE-2026-101333
Updated: 2026-09-28T15:18:17.300Z
Status : Awaiting Analysis
Published: 2026-09-28T15:17:13.260
Modified: 2026-09-28T16:26:58.700
Link: CVE-2026-101333
No data.
OpenCVE Enrichment
Updated: 2026-09-28T19:42:13Z
-
CWE-770
Allocation of Resources Without Limits or Throttling