Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded im…
cve CVE-2025-66033 1 source, 1 claim · Watch
NVD writes:
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in versi… the claim
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in versi… the claim
- Severity
- MEDIUM NVD
- CVSS
- 5.3 NVD
- Vendor
- okta NVD
- Product
- okta-sdk-java NVD
- CWE
- CWE-401 NVD
How far exploitation has got
- No public code known
- Proof of concept
- Proof of concept, verified
- A Metasploit module
- Exploited in the wild
- Used in ransomware campaigns
Timeline
| 2025-12-10 | first spoke of it: Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1. | NVD |
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1.
What it is to other things
| affects | okta/java_management_sdk NVD |
| made_by | okta NVD |
In words only, so not counted until a person confirms one:
| affects | okta/okta_sdk_javaNVD says “okta · okta-sdk-java” |
Every value, with what each source said and its receipt
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Automatable automatable | NVD | no At least one of those steps needs a person. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "okta-sdk-java",
"vendor": "okta",
"versions": [
{
"status": "affected",
"version": ">= 21.0.0, < 24.0.1"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
"versionEndExcluding": "24.0.1",
"versionStartIncluding": "21.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
},
{
"lang": "es",
"value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
}
],
"id": "CVE-2025-66033",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.6,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66033",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:40:05.587445Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:27.520",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-401"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS cvss | NVD | 5.3receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "okta-sdk-java",
"vendor": "okta",
"versions": [
{
"status": "affected",
"version": ">= 21.0.0, < 24.0.1"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
"versionEndExcluding": "24.0.1",
"versionStartIncluding": "21.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
},
{
"lang": "es",
"value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
}
],
"id": "CVE-2025-66033",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.6,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66033",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:40:05.587445Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:27.520",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-401"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS vector cvss_vector | NVD | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:Hreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "okta-sdk-java",
"vendor": "okta",
"versions": [
{
"status": "affected",
"version": ">= 21.0.0, < 24.0.1"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
"versionEndExcluding": "24.0.1",
"versionStartIncluding": "21.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
},
{
"lang": "es",
"value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
}
],
"id": "CVE-2025-66033",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.6,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66033",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:40:05.587445Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:27.520",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-401"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CWE cwe | NVD | CWE-401receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "okta-sdk-java",
"vendor": "okta",
"versions": [
{
"status": "affected",
"version": ">= 21.0.0, < 24.0.1"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
"versionEndExcluding": "24.0.1",
"versionStartIncluding": "21.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
},
{
"lang": "es",
"value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
}
],
"id": "CVE-2025-66033",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.6,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66033",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:40:05.587445Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:27.520",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-401"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Exploitation exploitation | NVD | none No evidence of exploitation, and no public proof of concept. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "okta-sdk-java",
"vendor": "okta",
"versions": [
{
"status": "affected",
"version": ">= 21.0.0, < 24.0.1"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
"versionEndExcluding": "24.0.1",
"versionStartIncluding": "21.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
},
{
"lang": "es",
"value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
}
],
"id": "CVE-2025-66033",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.6,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66033",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:40:05.587445Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:27.520",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-401"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Product product | NVD | okta-sdk-javareceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "okta-sdk-java",
"vendor": "okta",
"versions": [
{
"status": "affected",
"version": ">= 21.0.0, < 24.0.1"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
"versionEndExcluding": "24.0.1",
"versionStartIncluding": "21.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
},
{
"lang": "es",
"value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
}
],
"id": "CVE-2025-66033",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.6,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66033",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:40:05.587445Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:27.520",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-401"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity | NVD | MEDIUM From 4.0 to 6.9. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "okta-sdk-java",
"vendor": "okta",
"versions": [
{
"status": "affected",
"version": ">= 21.0.0, < 24.0.1"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
"versionEndExcluding": "24.0.1",
"versionStartIncluding": "21.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
},
{
"lang": "es",
"value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
}
],
"id": "CVE-2025-66033",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.6,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66033",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:40:05.587445Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:27.520",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-401"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | medium | ||||
| Status status | NVD | Analyzedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "okta-sdk-java",
"vendor": "okta",
"versions": [
{
"status": "affected",
"version": ">= 21.0.0, < 24.0.1"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
"versionEndExcluding": "24.0.1",
"versionStartIncluding": "21.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
},
{
"lang": "es",
"value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
}
],
"id": "CVE-2025-66033",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.6,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66033",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:40:05.587445Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:27.520",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-401"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Technical impact technical_impact | NVD | partial The attacker gains limited control, or limited information. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "okta-sdk-java",
"vendor": "okta",
"versions": [
{
"status": "affected",
"version": ">= 21.0.0, < 24.0.1"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
"versionEndExcluding": "24.0.1",
"versionStartIncluding": "21.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
},
{
"lang": "es",
"value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
}
],
"id": "CVE-2025-66033",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.6,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66033",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:40:05.587445Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:27.520",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-401"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | oktareceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "okta-sdk-java",
"vendor": "okta",
"versions": [
{
"status": "affected",
"version": ">= 21.0.0, < 24.0.1"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:okta:java_management_sdk:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23BCEB28-B29D-4F50-9BC4-CB2B9A59FBCC",
"versionEndExcluding": "24.0.1",
"versionStartIncluding": "21.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1."
},
{
"lang": "es",
"value": "El Okta Java Management SDK facilita las interacciones con la API de gestión de Okta. En las versiones 21.0.0 a la 24.0.0, implementaciones multihilo específicas pueden encontrar problemas de memoria ya que los hilos no se limpian correctamente después de que se completan las solicitudes. Con el tiempo, esto puede degradar el rendimiento y la disponibilidad en aplicaciones de larga ejecución y puede resultar en una condición de denegación de servicio bajo carga sostenida. Además de usar las versiones afectadas, los usuarios pueden estar en riesgo si están implementando una aplicación de larga ejecución usando el ApiClient de manera multihilo. Este problema está solucionado en la versión 24.0.1."
}
],
"id": "CVE-2025-66033",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.6,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66033",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:40:05.587445Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:27.520",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/okta/okta-sdk-java/commit/1daa9229a70fc38fb252aeaa637f82d0b0729b3f"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/okta/okta-sdk-java/security/advisories/GHSA-qhr6-6cgv-6638"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-401"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — |
Every claim, by kind
vulnerability
| Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1. zetlyn/cve-nvd · 2025-12-10 | automatable no cvss 5.3 cvss_vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H cwe CWE-401 exploitation none product okta-sdk-java severity MEDIUM status Analyzed technical_impact partial vendor okta | source |