Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-6563

22
FAUCET Score

CVE-2023-6563 is an unconstrained memory consumption vulnerability in Keycloak, affecting Red Hat Keycloak, Enterprise Linux, and OpenShift Container Platform. An authenticated attacker can trigger excessive memory and CPU consumption by accessing the "consents" tab in the admin UI, potentially crashing the system in environments with numerous offline tokens. With a CVSS score of 7.7 (High), this vulnerability has a network attack vector, low attack complexity, and high availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 21.0.0CPE matchmatch criteria
cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:*
7.6CPE matchmatch criteria
cpe:2.3:a:redhat:single_sign-on:7.6:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*
4.11CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:*
4.12CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.24%
Probability of exploitation in next 30 days
EPSS Percentile
66.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0124 is in the 63rd percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

mavenpatch availablevia ghsa
Product: org.keycloak:keycloak-model-jpaFixed in: 21.0.0
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.6 for RHEL 7Fixed in: rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.6 for RHEL 8Fixed in: rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Single Sign-On 7.6 for RHEL 9Fixed in: rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rh-sso-7/sso76-openshift-rhel8:7.6-38
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rh-sso-7/sso7-rhel8-operator-bundle:7.6.6-2
View patch
redhatpatch availablevia redhat_api
Product: Single Sign-On 7.6.6Fixed in: rh-sso7-keycloak
View patch
redhatvendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

mavenGHSA-54f3-c6hg-865hhigh

Allocation of Resources Without Limits in Keycloak

Dec 14, 2023
redhatCVE-2023-6563Important

keycloak: offline session token DoS

Dec 14, 2023

References

access.redhat.com / errata/RHSA-2023:7854
Vendor Advisory
access.redhat.com / errata/RHSA-2023:7855
Vendor Advisory
access.redhat.com / errata/RHSA-2023:7856
Vendor Advisory
access.redhat.com / errata/RHSA-2023:7857
Exploit
access.redhat.com / errata/RHSA-2023:7858
Vendor Advisory
access.redhat.com / security/cve/CVE-2023-6563
Vendor Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
github.com / keycloak/keycloak/issues/13340
Issue Tracking