CVE-2024-1249

Executive Summary

Keycloak OIDC component flaw in checkLoginIframe allows unvalidated cross‑origin messages. Attackers can send millions of requests in seconds, causing a denial‑of‑service. No origin validation is performed. Not listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 7.4 (HIGH) - Published: 2024-04-17T14:15:08.160 - Last Modified: 2026-09-08T20:17:25.350

Original Description: A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

"Kindness is the language which the deaf can hear and the blind can see."

— Mark Twain
Source: NVD