Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16100

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires an authenticated user with specific account management permissions. Successful exploitation allows an attacker to cause a denial of service by exhausting system memory through the creation of an unbounded number of metric time series. The vulnerability's root cause is the use of request-controlled, unsanitized input within Prometheus metric labels.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Data Grid 8keycloak-servicesNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesNot affected
Red Hat Single Sign-On 7keycloak-servicesNot affected
Red Hat build of Keycloak 26.6rhbk/keycloak-operator-bundleFixedRHSA-2026:5084905.08.2026
Red Hat build of Keycloak 26.6rhbk/keycloak-rhel9FixedRHSA-2026:5084905.08.2026
Red Hat build of Keycloak 26.6rhbk/keycloak-rhel9-operatorFixedRHSA-2026:5084905.08.2026
Red Hat build of Keycloak 26.6.5keycloak-servicesFixedRHSA-2026:5084805.08.2026
Red Hat build of Keycloak 26.6.5rhbk-keycloak-rhel9/rhbk-keycloak-rhel9FixedRHSA-2026:5084805.08.2026
Red Hat build of Keycloak 26.6.5rhbk-openshift-rhel9/rhbk-openshift-rhel9FixedRHSA-2026:5084805.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2501730keycloak-services: keycloak-services: Unbounded metric cardinality in user event metrics via request-controlled error text

EPSS

Процентиль: 23%
0.00307
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
10 дней назад

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.

CVSS3: 6.5
debian
10 дней назад

A flaw was found in the user-event metrics recording of Keycloak. When ...

CVSS3: 6.5
github
10 дней назад

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.

EPSS

Процентиль: 23%
0.00307
Низкий

6.5 Medium

CVSS3