CVE-2025-2559: Red Hat Build Of Keycloak
Medium severity, CVSS 4.9. EPSS: 0.7% chance of exploitation in the next 30 days.
A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfMemoryError. This issue could result in a denial of service condition, preventing legitimate users from accessing the system.
Affected products
- Red Hat Red Hat Build Of Keycloak
- Red Hat Red Hat Build Of Keycloak 26.0: before 26.0.11-2 (fixed in 26.0.11-2); before 26.0-12 (fixed in 26.0-12); before 26.0-13 (fixed in 26.0-13)
- Red Hat Red Hat Single Sign-On 7
Published 2025-03-25. Last modified 2026-09-21.