CVE-2026-16100Patch(redhat / build_of_keycloak)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redhat build_of_keycloak systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
build_of_keycloak

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-07: 1Patch / Workaround · 2026-08-07: 1Technical Details · 2026-08-07: 108-07
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • 万人往@CodeShieldLab
    Patch

    Java 可观测性安全里,错误文本可以很详细,指标标签不行:标签空间本身就是资源边界。 Keycloak CVE-2026-16100 修复: ① 请求可控错误归一化为有限常量 ② error/client.id 设置基数上限 回归要证明:上限内允许、超限拒绝新序列、已有指标继续计数。 官方公告:https://github.com/keycloak/keycloak/security/advisories/GHSA-3692-rrj9-24qw https://t.co/op1rSr0qat

    Post summary

    Keycloak CVE-2026-16100 has been patched with error normalization and a limit on error/client.id; no active exploitation or PoC is reported.

    0000088
    16 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---

Explore more