MEDIUM 6.5 Maven

org.keycloak:keycloak-services has Inefficient Regular Expression Complexity

GHSA-wq8x-cg39-8mrr · CVE-2024-10270

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.

Ready to move

Start Securing

Free, no credit card | First findings in minutes