Impact
The vulnerability resides in the Micrometer user‑event metrics listener of Keycloak, where inclusion of the idp tag allows an unauthenticated attacker to issue requests to the identity broker login endpoint with arbitrary provider aliases, resulting in the creation of an unlimited number of metric time series. This uncontrolled growth can consume excessive memory and degrade the performance of the server and its monitoring stack, effectively creating a denial‑of‑service condition. The weakness is identified as CWE‑770, unbounded resource creation.
Affected Systems
Vendors affected include Red Hat Build of Keycloak and Red Hat Single Sign‑On 7. No specific product versions are listed, so any deployment of these products may be impacted.
Risk and Exploitability
The CVSS score is 3.7, indicating low severity, and no EPSS data is available. The vulnerability is not listed in the CISA KEV catalog. Despite being untrusted input, the attack can be launched without authentication by sending crafted requests to the broker login endpoint, making it relatively easy to trigger. Overall risk is moderate because the impact is limited to performance degradation and memory exhaustion rather than direct compromise.
OpenCVE Enrichment