AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16100

MEDIUM · CVSS 6.5 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Keycloak's user-event metrics recording is vulnerable to a denial-of-service attack due to the logging of raw error messages from failed account operations as Prometheus metric labels. An authenticated user can exploit this flaw by generating numerous unique error messages, leading to memory exhaustion and potential service outages. Organizations using Keycloak with metrics enabled should prioritize addressing this vulnerability to prevent disruptions in service availability.

CVE
CVE-2026-16100
Severity
MEDIUM
CVSS
6.5
EPSS
0.31%

Original NVD Description

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.

Related CVEs

Other vulnerabilities affecting the same vendor(s)