CVE-2026-101333Low· 3.7▾ SunlitA flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker ca…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider aliases, causing the system to create an unlimited number of metric time series. This can lead to excessive memory consumption and degrade the performance of both the server and its monitoring tools.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-96448Medium· 6.6A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution
CVE-2026-97846Medium· 6.8Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate
CVE-2026-88359Medium· 6.5libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format()
CVE-2026-97311Medium· 4.3A flaw was found in the Admin REST API of Keycloak, an identity and access management solution
CVE-2026-97176Medium· 4.2A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution
CVE-2026-97177Medium· 6.6A flaw was found in the user update mechanism of the Keycloak Admin REST API