CVE-2024-10270

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.
Configurations

No configuration.

History

06 May 2026, 17:16

Type Values Removed Values Added
References
  • () https://github.com/advisories/GHSA-wq8x-cg39-8mrr -
  • () https://github.com/keycloak/keycloak/commit/5d6c91f3309db468b0fe4834e88c3d25649f73e4 -

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en el paquete Keycloak-services. Si se pasan datos no confiables al método SearchQueryUtils, podría generarse un escenario de denegación de servicio (DoS) al agotar los recursos del sistema debido a una complejidad de Regex.

25 Nov 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-25 08:15

Updated : 2026-05-06 17:16


NVD link : CVE-2024-10270

Mitre link : CVE-2024-10270

CVE.ORG link : CVE-2024-10270


JSON object : View

Products Affected

No product.

CWE
CWE-1333

Inefficient Regular Expression Complexity