Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on broker login endpoint
Published Sep 28, 2026
3.7
LOWCVSS 3.1
EPSS 0.23%
Description
A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider aliases, causing the system to create an unlimited number of metric time series. This can lead to excessive memory consumption and degrade the performance of both the server and its monitoring tools.
Affected products
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | affected |
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (3)
- https://access.redhat.com/security/cve/CVE-2026-101333 vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2542498 issue-trackingx_refsource_REDHAT
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88313 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-101333 | vdb-entryx_refsource_REDHAT | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2542498 | issue-trackingx_refsource_REDHAT | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88313 | Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data