The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth.
This vulnerability can result in a denial-of-service condition, causing service unavailability for deployments that utilize the Magic Link authenticator. The impact is limited to these specific deployments and requires repeated invalid authentication attempts to trigger.
References
| Link | Resource |
|---|---|
| https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4469/ | Vendor Advisory |
Configurations
History
27 May 2026, 19:34
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Wso2 identity Server
Wso2 |
|
| References | () https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4469/ - Vendor Advisory | |
| CPE | cpe:2.3:a:wso2:identity_server:*:*:*:*:*:*:*:* |
11 May 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-11 12:16
Updated : 2026-05-27 19:34
NVD link : CVE-2025-10470
Mitre link : CVE-2025-10470
CVE.ORG link : CVE-2025-10470
JSON object : View
Products Affected
wso2
- identity_server
CWE
CWE-400
Uncontrolled Resource Consumption
