Resource management error in Keycloak - CVE-2025-2559
Published: April 30, 2025
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application when caching JWT tokens. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely leading to denial of service.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2025-2559
Red Hat build of Keycloak - update to 26.0.11