CVE-2026-101333: Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on broker login endpoint

Published Sep 28, 2026
·
Updated

A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider aliases, causing the system to create an unlimited number of metric time series. This can lead to excessive memory consumption and degrade the performance of both the server and its monitoring tools.

Affected Software

1 affected component
Keycloak Keycloak

Event History

Sep 28, 2026
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Keycloak deployments using the Micrometer user-event metrics listener with the idp tag enabled are exposed. The affected endpoint is the identity broker login endpoint.

2

What does an attacker need to exploit it?

An attacker does not need authentication or user interaction. Exploitation requires sending requests to the identity broker login endpoint with arbitrary provider aliases.

3

What is the practical impact?

Requests using distinct provider aliases can cause unlimited metric time series creation. This may consume excessive memory and degrade the performance of the Keycloak server and connected monitoring tools.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203