CVE-2023-6563: Red Hat Keycloak

High severity, CVSS 7.7. EPSS: 1.2% chance of exploitation in the next 30 days.

An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.

Affected products

  • Red Hat Keycloak: before 21.0.0 (fixed in 21.0.0)
  • Red Hat Openshift Container Platform: version 4.11 only; version 4.12 only
  • Red Hat Openshift Container Platform For IBM Linuxone: version 4.9 only; version 4.10 only
  • Red Hat Openshift Container Platform For Power: version 4.9 only; version 4.10 only
  • Red Hat Single Sign-On: version 7.6 only; affected versions not specified

Published 2023-12-14. Last modified 2026-09-22.