Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded im…

cve CVE-2025-66033 1 source, 1 claim · Watch

NVD writes:
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in versi… the claim
Severity
MEDIUM NVD
CVSS
5.3 NVD
Vendor
okta NVD
Product
okta-sdk-java NVD
CWE
CWE-401 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2025-12-10first spoke of it: Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1.NVD

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1.

What it is to other things

affectsokta/java_management_sdk
NVD
made_byokta
NVD

In words only, so not counted until a person confirms one:

affectsokta/okta_sdk_java
NVD says “okta · okta-sdk-java”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCno
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "okta-sdk-java",
            "vendor": "okta",
            "versions": [
              {
                "status": "affected",
                "version": ">= 21.0.0, < 24.0.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
                "versionEndExcluding": "24.0.1",
                "versionStartIncluding": "21.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
      },
      {
        "lang": "es",
        "value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
      }
    ],
    "id": "CVE-2025-66033",
    "lastModified": "2026-09-25T23:10:00.463",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.6,
          "impactScore": 3.6,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-66033",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-11T15:40:05.587445Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-10T22:16:27.520",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-401"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
NVD5.3
receipt
Source
NVD
Its words
5.3
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "okta-sdk-java",
            "vendor": "okta",
            "versions": [
              {
                "status": "affected",
                "version": ">= 21.0.0, < 24.0.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
                "versionEndExcluding": "24.0.1",
                "versionStartIncluding": "21.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
      },
      {
        "lang": "es",
        "value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
      }
    ],
    "id": "CVE-2025-66033",
    "lastModified": "2026-09-25T23:10:00.463",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.6,
          "impactScore": 3.6,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-66033",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-11T15:40:05.587445Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-10T22:16:27.520",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-401"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "okta-sdk-java",
            "vendor": "okta",
            "versions": [
              {
                "status": "affected",
                "version": ">= 21.0.0, < 24.0.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
                "versionEndExcluding": "24.0.1",
                "versionStartIncluding": "21.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
      },
      {
        "lang": "es",
        "value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
      }
    ],
    "id": "CVE-2025-66033",
    "lastModified": "2026-09-25T23:10:00.463",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.6,
          "impactScore": 3.6,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-66033",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-11T15:40:05.587445Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-10T22:16:27.520",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-401"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
NVDCWE-401
receipt
Source
NVD
Its words
CWE-401
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCWE-401
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "okta-sdk-java",
            "vendor": "okta",
            "versions": [
              {
                "status": "affected",
                "version": ">= 21.0.0, < 24.0.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
                "versionEndExcluding": "24.0.1",
                "versionStartIncluding": "21.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
      },
      {
        "lang": "es",
        "value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
      }
    ],
    "id": "CVE-2025-66033",
    "lastModified": "2026-09-25T23:10:00.463",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.6,
          "impactScore": 3.6,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-66033",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-11T15:40:05.587445Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-10T22:16:27.520",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-401"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCnone
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "okta-sdk-java",
            "vendor": "okta",
            "versions": [
              {
                "status": "affected",
                "version": ">= 21.0.0, < 24.0.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
                "versionEndExcluding": "24.0.1",
                "versionStartIncluding": "21.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
      },
      {
        "lang": "es",
        "value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
      }
    ],
    "id": "CVE-2025-66033",
    "lastModified": "2026-09-25T23:10:00.463",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.6,
          "impactScore": 3.6,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-66033",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-11T15:40:05.587445Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-10T22:16:27.520",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-401"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDokta-sdk-java
receipt
Source
NVD
Its words
okta-sdk-java
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCokta-sdk-java
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "okta-sdk-java",
            "vendor": "okta",
            "versions": [
              {
                "status": "affected",
                "version": ">= 21.0.0, < 24.0.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
                "versionEndExcluding": "24.0.1",
                "versionStartIncluding": "21.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
      },
      {
        "lang": "es",
        "value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
      }
    ],
    "id": "CVE-2025-66033",
    "lastModified": "2026-09-25T23:10:00.463",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.6,
          "impactScore": 3.6,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-66033",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-11T15:40:05.587445Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-10T22:16:27.520",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-401"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDMEDIUM
From 4.0 to 6.9.
receipt
Source
NVD
Its words
MEDIUM
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCMEDIUM
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "okta-sdk-java",
            "vendor": "okta",
            "versions": [
              {
                "status": "affected",
                "version": ">= 21.0.0, < 24.0.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
                "versionEndExcluding": "24.0.1",
                "versionStartIncluding": "21.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
      },
      {
        "lang": "es",
        "value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
      }
    ],
    "id": "CVE-2025-66033",
    "lastModified": "2026-09-25T23:10:00.463",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.6,
          "impactScore": 3.6,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-66033",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-11T15:40:05.587445Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-10T22:16:27.520",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-401"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
medium
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "okta-sdk-java",
            "vendor": "okta",
            "versions": [
              {
                "status": "affected",
                "version": ">= 21.0.0, < 24.0.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
                "versionEndExcluding": "24.0.1",
                "versionStartIncluding": "21.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
      },
      {
        "lang": "es",
        "value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
      }
    ],
    "id": "CVE-2025-66033",
    "lastModified": "2026-09-25T23:10:00.463",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.6,
          "impactScore": 3.6,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-66033",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-11T15:40:05.587445Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-10T22:16:27.520",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-401"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCpartial
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "okta-sdk-java",
            "vendor": "okta",
            "versions": [
              {
                "status": "affected",
                "version": ">= 21.0.0, < 24.0.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
                "versionEndExcluding": "24.0.1",
                "versionStartIncluding": "21.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
      },
      {
        "lang": "es",
        "value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
      }
    ],
    "id": "CVE-2025-66033",
    "lastModified": "2026-09-25T23:10:00.463",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.6,
          "impactScore": 3.6,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-66033",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-11T15:40:05.587445Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-10T22:16:27.520",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-401"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDokta
receipt
Source
NVD
Its words
okta
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCokta
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "okta-sdk-java",
            "vendor": "okta",
            "versions": [
              {
                "status": "affected",
                "version": ">= 21.0.0, < 24.0.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
                "versionEndExcluding": "24.0.1",
                "versionStartIncluding": "21.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
      },
      {
        "lang": "es",
        "value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
      }
    ],
    "id": "CVE-2025-66033",
    "lastModified": "2026-09-25T23:10:00.463",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.6,
          "impactScore": 3.6,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-66033",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-11T15:40:05.587445Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-10T22:16:27.520",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-401"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1.
zetlyn/cve-nvd · 2025-12-10
automatable no cvss 5.3 cvss_vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H cwe CWE-401 exploitation none product okta-sdk-java severity MEDIUM status Analyzed technical_impact partial vendor okta source