Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101333— Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on broker login endpoint

Quick assessment

Affected
Red Hat Red Hat Build of Keycloak
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Keycloak(一种集成的身份和访问管理解决方案)的 Micrometer 用户事件指标监听器中存在一个漏洞。当该监听器被配置为包含 标签时,此问题会发生。未经身份验证的攻击者可以向身份代理登录端点发送请求,并使用任意提供程序别名,导致系统创建无限数量的指标时间序列。这可能引发过度的内存消耗,从而降低服务器及其监控工具的性能。

CVSS 3.7 · Low
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101333

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on broker login endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider aliases, causing the system to create an unlimited number of metric time series. This can lead to excessive memory consumption and degrade the performance of both the server and its monitoring tools.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Build of Keycloak - cpe:/a:redhat:build_keycloak:
Red Hat Red Hat Build of Keycloak - cpe:/a:redhat:build_keycloak:
Red Hat Red Hat Single Sign-On 7 - cpe:/a:redhat:red_hat_single_sign_on:7

II. Public POCs for CVE-2026-101333

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101333

请登录查看更多情报信息。

Other References for CVE-2026-101333 (2)

Same Patch Batch · Red Hat · 2026-09-28 · 3 CVEs total

CVE-2026-101292 8.2 HIGH Artemis-core-client: unsafe reflection in apache activemq artemis federation message deser
CVE-2026-86330 7.2 HIGH Noobaa-core: noobaa-core: os command injection in cluster_internal_api.set_hostname_intern

IV. Related Vulnerabilities

V. Comments for CVE-2026-101333

No comments yet


Leave a comment