CVE-2026-16100
Received Received - Intake

Keycloak Metrics Memory Exhaustion via User Input

Vulnerability report for CVE-2026-16100, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Red Hat, Inc.

Description

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
redhat keycloak *
keycloak keycloak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Keycloak's metrics system recording raw error messages from failed account operations as Prometheus metric labels. Authenticated users can exploit this by submitting many unique inputs like nonexistent client IDs, creating excessive metric entries that exhaust system memory, leading to service crashes or unavailability.

Detection Guidance

Monitor Prometheus metrics for unusually high label cardinality or memory exhaustion in Keycloak. Check Keycloak logs for excessive error messages related to user operations.

Impact Analysis

If you use Keycloak with metrics enabled, an attacker could crash your authentication service by flooding it with unique error messages. This would disrupt user access, cause downtime, and potentially lead to denial-of-service conditions affecting your applications.

Compliance Impact

This vulnerability could impact compliance by causing service disruptions that violate availability requirements in GDPR or HIPAA. Downtime may lead to unauthorized access risks or failure to meet uptime obligations, potentially resulting in regulatory penalties or data protection violations.

Mitigation Strategies

Disable metrics recording if not required. If metrics are needed, restrict label values to prevent user-supplied input. Update Keycloak to the latest patched version as soon as available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16100. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart