Resource exhaustion in Keycloak - CVE-2026-16100
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in user-event metrics recording when processing failed account operations with request-controlled error text. A remote user can submit crafted requests with unique input values to cause a denial of service.
Only instances with metrics enabled are vulnerable.