Description
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
Published: 2025-12-10
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j5gq-897m-2rff Race condition in the Okta Java SDK
History

Fri, 06 Mar 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Okta java Management Sdk
CPEs cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*
Vendors & Products Okta java Management Sdk

Thu, 11 Dec 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Okta
Okta sdk-java
Vendors & Products Okta
Okta sdk-java

Thu, 11 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 10 Dec 2025 22:30:00 +0000

Type Values Removed Values Added
Description Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
Title Race condition in the Okta Java SDK
Weaknesses CWE-362
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Okta Java Management Sdk Sdk-java
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-11T15:38:07.664Z

Reserved: 2025-12-08T21:36:28.779Z

Link: CVE-2025-67505

cve-icon Vulnrichment

Updated: 2025-12-11T15:38:04.240Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-10T23:15:48.667

Modified: 2026-03-06T19:42:22.223

Link: CVE-2025-67505

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-11T16:20:10Z

Weaknesses