CVE-2023-6563: Red Hat Keycloak
High severity, CVSS 7.7. EPSS: 1.2% chance of exploitation in the next 30 days.
An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.
Affected products
- Red Hat Keycloak: before 21.0.0 (fixed in 21.0.0)
- Red Hat Openshift Container Platform: version 4.11 only; version 4.12 only
- Red Hat Openshift Container Platform For IBM Linuxone: version 4.9 only; version 4.10 only
- Red Hat Openshift Container Platform For Power: version 4.9 only; version 4.10 only
- Red Hat Single Sign-On: version 7.6 only; affected versions not specified
Published 2023-12-14. Last modified 2026-09-22.