CVE-2025-2559: Red Hat Build Of Keycloak

Medium severity, CVSS 4.9. EPSS: 0.7% chance of exploitation in the next 30 days.

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfMemoryError. This issue could result in a denial of service condition, preventing legitimate users from accessing the system.

Affected products

  • Red Hat Red Hat Build Of Keycloak
  • Red Hat Red Hat Build Of Keycloak 26.0: before 26.0.11-2 (fixed in 26.0.11-2); before 26.0-12 (fixed in 26.0-12); before 26.0-13 (fixed in 26.0-13)
  • Red Hat Red Hat Single Sign-On 7

Published 2025-03-25. Last modified 2026-09-21.