THREAT OPS › Threat News › [NVD] CVE-2025-2559 (MEDIUM 4.9) — A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOf
[NVD] CVE-2025-2559 (MEDIUM 4.9) — A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOf
CVE-2025-2559 CVSS: 4.9 MEDIUM Published: 2025-03-25T09:15:17.047
A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfMemoryError. This issue could result in a denial of s
Indicators of compromise
- CVE-2025-2559cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-2559