Description
A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.
Published: 2026-08-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

When user‑event metrics are enabled, Keycloak records raw error messages from failed account operations as Prometheus metric labels. These error messages can contain user‑supplied values such as nonexistent client IDs. An authenticated user can therefore create a vast number of unique metric labels, causing the service to exhaust memory and crash or become unavailable. This vulnerability delivers a denial of service to the Keycloak instance or dependent services and is an example of excessive resource consumption (CWE‑770).

Affected Systems

Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7 are all vulnerable when user‑event metrics are enabled. The CNA data does not list specific product versions, so current releases that expose these metrics should be assessed.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score is not provided, leaving exploitation probability uncertain. The vulnerability is not in the CISA KEV catalog. An attacker must be authenticated and can create a large number of metric labels, but the exploit requires sufficient memory resources to trigger a crash. No effective workaround is available according to Red Hat’s product security criteria, so remediation relies on disabling metrics, limiting label cardinality, or monitoring for service degradation.

Generated by OpenCVE AI on August 5, 2026 at 21:43 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Disable user‑event metric recording or configure the telemetry settings to strip raw error strings from metric labels.
  • Limit Prometheus label cardinality by configuring Keycloak to cap unique label values or to sanitize errors before labeling.
  • If the service cannot be stopped, monitor memory consumption and metric cardinality; restart or scale the service when thresholds are exceeded.
  • Check the Red Hat product security site regularly for an official patch and apply it promptly when released.
  • Since no interim workaround satisfies Red Hat security criteria, no temporary fix is available; continue monitoring for official updates.

Generated by OpenCVE AI on August 5, 2026 at 21:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On
Vendors & Products Redhat build Of Keycloak
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On

Thu, 06 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 05 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak: cpe:/a:redhat:build_keycloak:26.6::el9
References

Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Wed, 05 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.
Title Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid 8 Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-05T18:45:38.602Z

Reserved: 2026-07-17T14:26:03.169Z

Link: CVE-2026-16100

cve-icon Vulnrichment

Updated: 2026-08-05T17:38:13.432Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T15:16:37.573

Modified: 2026-08-10T18:17:35.247

Link: CVE-2026-16100

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-05T02:02:00Z

Links: CVE-2026-16100 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:06:22Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling