A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimately resulting in a Denial of Service (DoS) for the Keycloak server.
The product has a loop body or loop condition that contains a control element that directly or indirectly consumes platform resources, e.g. messaging, sessions, locks, or file descriptors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Build_of_keycloak | Redhat | - (including) | - (including) |
| Build_of_keycloak | Redhat | 26.2 (including) | 26.2 (including) |
| Build_of_keycloak | Redhat | 26.2.15 (including) | 26.2.15 (including) |
| Build_of_keycloak | Redhat | 26.4 (including) | 26.4 (including) |
| Build_of_keycloak | Redhat | 26.4.11 (including) | 26.4.11 (including) |
| Red Hat build of Keycloak 26.2 | RedHat | rhbk/keycloak-operator-bundle:26.2.15-1 | * |
| Red Hat build of Keycloak 26.2 | RedHat | rhbk/keycloak-rhel9:26.2-18 | * |
| Red Hat build of Keycloak 26.2 | RedHat | rhbk/keycloak-rhel9-operator:26.2-18 | * |
| Red Hat build of Keycloak 26.2.15 | RedHat | rhbk/keycloak-rhel9 | * |
| Red Hat build of Keycloak 26.4 | RedHat | rhbk/keycloak-operator-bundle:26.4.11-1 | * |
| Red Hat build of Keycloak 26.4 | RedHat | rhbk/keycloak-rhel9:26.4-14 | * |
| Red Hat build of Keycloak 26.4 | RedHat | rhbk/keycloak-rhel9-operator:26.4-14 | * |
| Red Hat build of Keycloak 26.4.11 | RedHat | rhbk/keycloak-rhel9 | * |