← voltar
CVE-2025-2559mediumCWE-770

Org.keycloak/keycloak-services: jwt token cache exhaustion leading to denial of service (dos) in keycloak

13Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 4.9epss 0.7%
probabilidade de exploração
0.7%top 49% das CVEs
exploração observada
nãonenhuma fonte reporta
A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfMemoryError. This issue could result in a denial of service condition, preventing legitimate users from accessing the system.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H