Description
A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitrary locale tags from unauthenticated requests and stores them in a permanent in-memory cache without limits. An attacker can exploit this by sending a large number of unique locale tags, eventually causing the server to run out of memory and crash.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A flaw in the theme localization endpoints of keycloak‑services allows an attacker to submit arbitrary locale tags from an unauthenticated connection. The service stores these tags in a permanent in‑memory cache without any limits, causing unchecked growth of memory consumption. Sending a large number of unique tags eventually exhausts the server’s memory, leading to a crash and service outage. The underlying weakness is an unbounded resource allocation vulnerability (CWE‑400).

Affected Systems

Affected by this vulnerability are Red Hat Single Sign‑On 7 and Red Hat build of Keycloak versions 26.4, 26.4.16, 26.6, and 26.6.7. The problem exists within the keycloak‑services component that handles authentication flows and theme management.

Risk and Exploitability

The severity score of 7.5 indicates a high‑risk denial of service condition. The exploitation probability, as shown by an EPSS score of less than 1 %, is low but non‑zero, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is readily available over the network, as the endpoint accepts unauthenticated requests, and an attacker can trigger resource exhaustion by repeatedly requesting the localization endpoint with distinct locale tags.

Generated by OpenCVE AI on September 18, 2026 at 01:43 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Update keycloak‑services by applying the Red Hat errata RHSA‑2026:68276, RHSA‑2026:68277, RHSA‑2026:68278, or RHSA‑2026:68280, which include the patch for unbounded locale caching.
  • Restart the Keycloak server after the update to clear any existing in‑memory cache and ensure the new limits are in effect.
  • If an update is not immediately available, restrict external access to the keycloak‑services locale endpoint with a firewall or reverse proxy to limit the rate of incoming requests and reduce the chance of resource exhaustion.

Generated by OpenCVE AI on September 18, 2026 at 01:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak: cpe:/a:redhat:build_keycloak:26.4::el9
cpe:/a:redhat:build_keycloak:26.6::el9
References

Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitrary locale tags from unauthenticated requests and stores them in a permanent in-memory cache without limits. An attacker can exploit this by sending a large number of unique locale tags, eventually causing the server to run out of memory and crash.
Title Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-400
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Build Keycloak Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-25T06:52:01.567Z

Reserved: 2026-08-25T10:38:42.346Z

Link: CVE-2026-79651

cve-icon Vulnrichment

Updated: 2026-09-16T15:36:11.330Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:52.000

Modified: 2026-09-16T19:42:43.623

Link: CVE-2026-79651

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T13:18:07Z

Links: CVE-2026-79651 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T01:45:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption