CVE-2024-10270

Executive Summary

CVE-2024-10270 exposes a denial‑of‑service flaw in Keycloak’s SearchQueryUtils: untrusted input can trigger an excessively complex regular expression, exhausting CPU and memory resources. The vulnerability can be exploited by attackers to crash or degrade Keycloak services, impacting availability of authentication and authorization functions.


Authoritative CVE Metadata - CVSS Base Score: 6.5 (MEDIUM) - Published: 2024-11-25T08:15:03.747 - Last Modified: 2026-08-31T01:16:42.347

Original Description: A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.

"You only lose what you cling to."

— Buddha
Source: NVD