CVE-2026-16100Medium· 6.5▾ SunlitA flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-s…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 31.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.
build_of_keycloak >= 26.6, < 26.6.5Upgrade past the affected range:
build_of_keycloak 26.6.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-16071Medium· 5.4A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories
CVE-2026-15573High· 8.1A flaw was found in Keycloak's Authorization Services
CVE-2026-16102High· 8.1A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution
CVE-2026-9798Medium· 4.3A flaw was found in Keycloak, an open-source identity and access management solution
CVE-2026-9793Medium· 5.9A flaw was found in Keycloak
CVE-2026-9689Medium· 4.2A flaw was found in Keycloak, an open-source identity and access management solution