CVE-2025-10470Disclosure(wso2 / identity_server)

LOWCVSS 8.6 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch wso2 identity_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. This vulnerability can result in a denial-of-service condition, causing service unavailability for deployments that utilize the Magic Link authenticator. The impact is limited to these specific deployments and requires repeated invalid authentication attempts to trigger.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_server

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
identity_server

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-11: 3Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-11: 205-11
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-10470 The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory… https://www.cve.org/CVERecord?id=CVE-2025-10470

    Post summary

    The post announces CVE‑2025‑10470 as a resource exhaustion issue in Magic Link authentication, providing a brief description and a link to the CVE record but no PoC, exploit, patch or evidence of active exploitation.

    00000626
    57.5K followersView on X
  • Entity@0x2ed3bb60
    Patch

    🚨 CVE-2025-10470: Magic Link authentication allows uncontrolled memory exhaustion via repeated invalid requests. No rate limiting. DoS condition confirmed. Patch or disable Magic Link deployments. https://0x2ed3bb60.xyz/threat/0df115b9c9a11fb0

    Post summary

    CVE-2025-10470 triggers memory exhaustion DoS attacks via Magic Link authentication, and a patch or disabling of Magic Link is advised.

    00000200
    7 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-10470 Denial-of-Service via Uncontrolled Memory Growth in Magic Link Authentication Flow https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-10470

    Post summary

    The text announces CVE‑2025‑10470, describing a denial‑of‑service vulnerability caused by uncontrolled memory growth during a magic link authentication flow.

    00000566
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwso2identity_server---

Explore more