Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8064 | A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfMemoryError. This issue could result in a denial of service condition, preventing legitimate users from accessing the system. |
Github GHSA |
GHSA-2935-2wfm-hhpv | Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache |
Wed, 06 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 30 Apr 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:build_keycloak:26 | |
| References |
|
Tue, 29 Apr 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:build_keycloak:26.0::el9 | |
| References |
|
Mon, 31 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Mar 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 25 Mar 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfMemoryError. This issue could result in a denial of service condition, preventing legitimate users from accessing the system. | |
| Title | Org.keycloak/keycloak-services: jwt token cache exhaustion leading to denial of service (dos) in keycloak | |
| First Time appeared |
Redhat
Redhat build Keycloak Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:/a:redhat:build_keycloak: cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat build Keycloak Redhat red Hat Single Sign On |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-05-06T16:48:50.818Z
Reserved: 2025-03-20T12:22:59.504Z
Link: CVE-2025-2559
Updated: 2025-03-31T16:31:55.723Z
Status : Deferred
Published: 2025-03-25T09:15:17.047
Modified: 2026-05-06T17:16:19.593
Link: CVE-2025-2559
OpenCVE Enrichment
No data.
EUVD
Github GHSA