Back

LOW

Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on broker login endpoint

Published Sep 28, 2026

Description

A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider aliases, causing the system to create an unlimited number of metric time series. This can lead to excessive memory consumption and degrade the performance of both the server and its monitoring tools.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Sep 28, 2026
Updated Sep 28, 2026
Reserved Sep 28, 2026

CISA Vulnrichment

Updated Sep 28, 2026

NVD

Status Awaiting Analysis
Modified Sep 28, 2026

Red Hat

No data

ENISA EUVD

Assigner redhat
Published Sep 28, 2026
Updated Sep 28, 2026

GitHub

No data