Description
A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider aliases, causing the system to create an unlimited number of metric time series. This can lead to excessive memory consumption and degrade the performance of both the server and its monitoring tools.
Published: 2026-09-28
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: Denial of Service via resource exhaustion
Action: Monitor
AI Analysis

Impact

The vulnerability resides in the Micrometer user‑event metrics listener of Keycloak, where inclusion of the idp tag allows an unauthenticated attacker to issue requests to the identity broker login endpoint with arbitrary provider aliases, resulting in the creation of an unlimited number of metric time series. This uncontrolled growth can consume excessive memory and degrade the performance of the server and its monitoring stack, effectively creating a denial‑of‑service condition. The weakness is identified as CWE‑770, unbounded resource creation.

Affected Systems

Vendors affected include Red Hat Build of Keycloak and Red Hat Single Sign‑On 7. No specific product versions are listed, so any deployment of these products may be impacted.

Risk and Exploitability

The CVSS score is 3.7, indicating low severity, and no EPSS data is available. The vulnerability is not listed in the CISA KEV catalog. Despite being untrusted input, the attack can be launched without authentication by sending crafted requests to the broker login endpoint, making it relatively easy to trigger. Overall risk is moderate because the impact is limited to performance degradation and memory exhaustion rather than direct compromise.

Generated by OpenCVE AI on September 28, 2026 at 15:21 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Upgrade to the latest Red Hat Build of Keycloak that contains the Micrometer listener fix.
  • If an upgrade is not immediately feasible, reconfigure the Micrometer listener to exclude the idp tag or disable the listener entirely to prevent new metric series from being created.
  • Apply resource limits to the Keycloak process (e.g., container memory limits) so that memory exhaustion cannot bring the service down.
  • Continuously monitor metric storage and system memory usage for abnormal growth and be prepared to block further requests if thresholds are exceeded.

Generated by OpenCVE AI on September 28, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat single Sign-on
Vendors & Products Redhat build Of Keycloak
Redhat single Sign-on

Mon, 28 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider aliases, causing the system to create an unlimited number of metric time series. This can lead to excessive memory consumption and degrade the performance of both the server and its monitoring tools.
Title Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on broker login endpoint
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-770
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-28T15:18:21.493Z

Reserved: 2026-09-28T14:09:11.117Z

Link: CVE-2026-101333

cve-icon Vulnrichment

Updated: 2026-09-28T15:18:17.300Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-28T15:17:13.260

Modified: 2026-09-28T16:26:58.700

Link: CVE-2026-101333

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:42:13Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling