THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-2559 (MEDIUM 4.9) — A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOf

[NVD] CVE-2025-2559 (MEDIUM 4.9) — A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOf

lownvdPublished 2025-03-25

CVE-2025-2559 CVSS: 4.9 MEDIUM Published: 2025-03-25T09:15:17.047

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfMemoryError. This issue could result in a denial of s

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-2559