LOW 3.7 NVD
CVE-2026-101333
A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the
A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider aliases, causing the system to create an unlimited number of metric time series. This can lead to excessive memory consumption and degrade the performance of both the server and its monitoring tools.
References
- https://access.redhat.com/security/cve/CVE-2026-101333
- https://bugzilla.redhat.com/show_bug.cgi?id=2542498
This low severity vulnerability with a CVSS score of 3.7 was published on 2026-09-28 via NVD.
vulnfeed aggregates 13625 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.