VDB
Sign up
HIGH7.5

GHSA-h4wv-g838-66g3

Keycloak: Application-Level DoS via Scope Processing

Quick fix

GHSA-h4wv-g838-66g3 — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.

# pom.xml: bump <version>26.5.7</version> for org.keycloak:keycloak-services

Details

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a Denial of Service (DoS) for the Keycloak server.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-services
Introduced in: 0Fixed in: 26.5.7
Fix# pom.xml: bump <version>26.5.7</version> for org.keycloak:keycloak-services

References