Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-16100

Опубликовано: 05 авг. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*
Версия от 26.6 (включая) до 26.6.5 (исключая)

EPSS

Процентиль: 23%
0.00307
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 6.5
redhat
11 дней назад

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.

CVSS3: 6.5
debian
10 дней назад

A flaw was found in the user-event metrics recording of Keycloak. When ...

CVSS3: 6.5
github
10 дней назад

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.

EPSS

Процентиль: 23%
0.00307
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-770