CVE-2025-21085: Ping Identity Pingfederate

Low severity, CVSS 2.1. EPSS: 0.3% chance of exploitation in the next 30 days.

PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory utilization.

Affected products

  • Ping Identity Pingfederate: from 12.2.0, before 12.2.4 (fixed in 12.2.4); from 12.1.0, before 12.1.9 (fixed in 12.1.9); from 12.0, before 12.0.9 (fixed in 12.0.9); from 11.3.0, before 11.3.13 (fixed in 11.3.13)

Published 2025-06-15. Last modified 2026-06-17.