Impact
When user‑event metrics are enabled, Keycloak records raw error messages from failed account operations as Prometheus metric labels. These error messages can contain user‑supplied values such as nonexistent client IDs. An authenticated user can therefore create a vast number of unique metric labels, causing the service to exhaust memory and crash or become unavailable. This vulnerability delivers a denial of service to the Keycloak instance or dependent services and is an example of excessive resource consumption (CWE‑770).
Affected Systems
Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7 are all vulnerable when user‑event metrics are enabled. The CNA data does not list specific product versions, so current releases that expose these metrics should be assessed.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score is not provided, leaving exploitation probability uncertain. The vulnerability is not in the CISA KEV catalog. An attacker must be authenticated and can create a large number of metric labels, but the exploit requires sufficient memory resources to trigger a crash. No effective workaround is available according to Red Hat’s product security criteria, so remediation relies on disabling metrics, limiting label cardinality, or monitoring for service degradation.
OpenCVE Enrichment