Impact
A flaw in the theme localization endpoints of keycloak‑services allows an attacker to submit arbitrary locale tags from an unauthenticated connection. The service stores these tags in a permanent in‑memory cache without any limits, causing unchecked growth of memory consumption. Sending a large number of unique tags eventually exhausts the server’s memory, leading to a crash and service outage. The underlying weakness is an unbounded resource allocation vulnerability (CWE‑400).
Affected Systems
Affected by this vulnerability are Red Hat Single Sign‑On 7 and Red Hat build of Keycloak versions 26.4, 26.4.16, 26.6, and 26.6.7. The problem exists within the keycloak‑services component that handles authentication flows and theme management.
Risk and Exploitability
The severity score of 7.5 indicates a high‑risk denial of service condition. The exploitation probability, as shown by an EPSS score of less than 1 %, is low but non‑zero, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is readily available over the network, as the endpoint accepts unauthenticated requests, and an attacker can trigger resource exhaustion by repeatedly requesting the localization endpoint with distinct locale tags.
OpenCVE Enrichment