CVE-2025-21085CWE-462

PingFederate OAuth Grant attribute duplication may use excessive memory

Low · published June 15, 2025

CVSS v4.0
2.1
EPSS
0%
Percentile
23.0
In the wild
Unconfirmed
What it is

PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory utilization.

The record
Technical detail
CVSS v4.0
2.1 · LOW
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/S:P/AU:Y/R:A/RE:L/U:Amber
EPSS
0.00306 · 23.0th percentile
Weakness
CWE-462 · Duplicate Key in Associative List (Alist)
Published
2025-06-15T14:25Z
EPSS history
Timeline
  • 15 JUN 14:25Z
    PingFederate OAuth Grant attribute duplication may use excessive memory
    cvelistv5