Intel

AIKIDO-2026-10306

keycloak-services is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-2575 Published Mar 9, 2026

50

Medium Risk

This Affects:

javakeycloak-services
0.0.1 - 26.5.3
Fixed in 26.5.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a Denial of Service (DoS). The application does not enforce size limits when decompressing SAMLRequest messages received via the SAML Redirect Binding. An unauthenticated remote attacker can send a highly compressed request that expands significantly during DEFLATE decompression, potentially causing excessive memory consumption and triggering an OutOfMemoryError, leading to process termination.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

keycloak-services is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 26.5.3.

How to fix this

Upgrade the org.keycloak:keycloak-services library to a patch version.