Red HatCVE-2026-101333
Red Hat Micrometer user-event metrics listener of Keycloak: resource exhaustion
Low3.7CVE-2026-101333 · Published Sep 28, 2026
A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider aliases, causing the system to create an unlimited number of metric time series. This can lead to excessive memory consumption and degrade the performance of both the server and its monitoring tools.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Build of Keycloak Product | all versions | No fix yet |
| all versions | No fix yet | |
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-770
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 28 | Red Hat Enterprise Linux: denial of service | Low3.6 | No fix yet |
| Sep 28 | Flatpak writes the OCI repository authentication token with world-readable... | Low3.2 | No fix yet |
| Sep 28 | Red Hat Enterprise Linux: denial of service | Low3.9 | No fix yet |
| Sep 28 | Red Hat Enterprise Linux: path traversal | High7.1 | No fix yet |
| Sep 28 | Red Hat GCC.: use after free | High7.0 | No fix yet |
| Sep 28 | A flaw was found in the StreamsHub Console for Apache Kafka | Medium6.5 | 0.12.9+1 more |