← Back

CVE-2025-10470

nvd nist
Published: May 11, 2026Modified: May 27, 2026

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. This vulnerability can result in a denial-of-service condition, causing service unavailability for deployments that utilize the Magic Link authenticator. The impact is limited to these specific deployments and requires repeated invalid authentication attempts to trigger.

Affected (1)

1 product
Identity Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 7.0.0 to 7.0.0.121

References (1)

Timeline

No history available yet.