rmartinc

2 exploits Active since Aug 2022
CVE-2025-2559 WRITEUP MEDIUM WRITEUP
Keycloak - Denial of Service via JWT Token Cache Exhaustion
A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfMemoryError. This issue could result in a denial of service condition, preventing legitimate users from accessing the system.
CVSS 4.9
CVE-2021-3859 WRITEUP HIGH WRITEUP
Undertow - Denial of Service
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
CVSS 7.5