{"id":"CVE-2025-67505","aliases":["GHSA-j5gq-897m-2rff"],"title":"Race condition in the Okta Java SDK","summary":"Race condition in the Okta Java SDK","severity":"high","cvss":8.4,"cwe":["CWE-362"],"vendor":"okta","product":"com.okta.sdk:okta-sdk-root","ecosystem":"maven","affected":["com.okta.sdk:okta-sdk-root >= 11.0.0, <= 20.0.0"],"patched":["com.okta.sdk:okta-sdk-root 20.0.1"],"published":"2025-12-10","updated":"2026-09-15","sourceUpdated":"2026-09-15T11:05:12Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-j5gq-897m-2rff","references":[{"url":"https://github.com/okta/okta-sdk-java/security/advisories/GHSA-j5gq-897m-2rff"},{"url":"https://github.com/okta/okta-sdk-java/commit/abf4f128a0441f90cb7efcdcf4bde1aef8703243"},{"url":"https://github.com/advisories/GHSA-j5gq-897m-2rff"}],"tags":["ghsa","maven"],"epss":0.00207,"epssPercentile":0.11149,"ingestedAt":"2026-09-15T11:36:07.421Z","slug":"CVE-2025-67505","body":"## Overview\n\n### Description\nIn the Okta Java SDK, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response.\n\n\n### Affected product and versions\nYou may be affected if you meet the following preconditions:\n- Using the Okta Java SDK between versions 11.0.0 and 20.0.0, and\n- Implementing a multithreaded application with the ApiClient class where the response status code is used in access control flows\n\n### Resolution\nUpgrade Okta/okta-sdk-java to versions 21.0.0  or greater.\n\n## Affected packages\n\n- `com.okta.sdk:okta-sdk-root >= 11.0.0, <= 20.0.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `com.okta.sdk:okta-sdk-root 20.0.1`","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":46.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}