A flaw was found in Keycloak. This vulnerability allows an unauthenticated remote attacker to cause a denial of service (DoS) by repeatedly initiating TLS 1.2 client-initiated renegotiation requests to exhaust server CPU resources, making the service unavailable.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.keycloak:keycloak-quarkus-dist(Maven) | 0 | 26.0.16 | N/A |
| org.keycloak:keycloak-quarkus-dist(Maven) | 26.1.0 | 26.2.10 | N/A |
| org.keycloak:keycloak-quarkus-dist(Maven) | 26.3.0 | 26.4.1 | N/A |
CVSS Metrics