---
id: CVE-2024-10270
title: A vulnerability was found in the Keycloak-services package
summary: >-
  A vulnerability was found in the Keycloak-services package. If untrusted data
  is passed to the SearchQueryUtils method, it could lead to a denial of service
  (DoS) scenario by exhausting system resources due to a Regex complexity.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-1333
vendor: Red Hat
product: keycloak
affected:
  - keycloak < 24.0.9
  - keycloak >= 25.0.0 < 26.0.6
  - rhbk/keycloak-operator-bundle (all versions)
  - rhbk/keycloak-rhel9 (all versions)
  - rhbk/keycloak-rhel9-operator (all versions)
  - build_of_keycloak_24.0.9
  - rhbk/keycloak-operator-bundle (all versions)
  - rhbk/keycloak-rhel9 (all versions)
  - rhbk/keycloak-rhel9-operator (all versions)
  - build_of_keycloak_26.0.6
  - keycloak-services
  - keycloak-services
  - keycloak-services
published: '2024-11-25'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T06:16:56.893'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-10270'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:10175'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:10176'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:10177'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:10178'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2024-10270'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2321214'
    label: secalert@redhat.com
  - url: 'https://github.com/advisories/GHSA-wq8x-cg39-8mrr'
    label: secalert@redhat.com
  - url: >-
      https://github.com/keycloak/keycloak/commit/5d6c91f3309db468b0fe4834e88c3d25649f73e4
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-10270.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-10270'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-10270'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2024-11-25T17:15:02.524794Z'
epss: 0.01255
epssPercentile: 0.68244
ingestedAt: '2026-08-04T07:38:00.085Z'
patched:
  - build_of_keycloak 24
  - build_of_keycloak 26.0
  - build_of_keycloak 24.0.9
  - build_of_keycloak 26.0.6
---

## Overview

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2024:10175** · Red Hat · fixed in: Red Hat build of Keycloak 24 · released 2024-11-21 · [advisory](https://access.redhat.com/errata/RHSA-2024:10175)
- **RHSA-2024:10177** · Red Hat · fixed in: Red Hat build of Keycloak 26.0 · released 2024-11-21 · [advisory](https://access.redhat.com/errata/RHSA-2024:10177)
- **RHSA-2024:10176** · Red Hat · fixed in: Red Hat build of Keycloak 24.0.9 · released 2024-11-21 · [advisory](https://access.redhat.com/errata/RHSA-2024:10176)
- **RHSA-2024:10178** · Red Hat · fixed in: Red Hat build of Keycloak 26.0.6 · released 2024-11-21 · [advisory](https://access.redhat.com/errata/RHSA-2024:10178)
- **Red Hat VEX** · Moderate · affected: Red Hat Single Sign-On 7 · no fix planned: Red Hat Single Sign-On 7 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-10270.json)
