CVE-2026-101333: Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on broker login endpoint
A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider aliases, causing the system to create an unlimited number of metric time series. This can lead to excessive memory consumption and degrade the performance of both the server and its monitoring tools.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Keycloak deployments using the Micrometer user-event metrics listener with the idp tag enabled are exposed. The affected endpoint is the identity broker login endpoint.
What does an attacker need to exploit it?
An attacker does not need authentication or user interaction. Exploitation requires sending requests to the identity broker login endpoint with arbitrary provider aliases.
What is the practical impact?
Requests using distinct provider aliases can cause unlimited metric time series creation. This may consume excessive memory and degrade the performance of the Keycloak server and connected monitoring tools.