Allocation of Resources Without Limits or Throttling in Vert.x - CVE-2026-6860
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the server-side SNI SslContext cache when handling TLS connections with server name indication. A remote attacker can send TLS connections with distinct server name indications to cause a denial of service.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-6860
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.4