The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth.
This vulnerability can result in a denial-of-service condition, causing service unavailability for deployments that utilize the Magic Link authenticator. The impact is limited to these specific deployments and requires repeated invalid authentication attempts to trigger.
Metrics
Affected Vendors & Products
References
History
Mon, 11 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. This vulnerability can result in a denial-of-service condition, causing service unavailability for deployments that utilize the Magic Link authenticator. The impact is limited to these specific deployments and requires repeated invalid authentication attempts to trigger. | |
| Title | Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Unavailability | |
| First Time appeared |
Wso2
Wso2 wso2 Carbon Magiclink Authenticator Module Wso2 wso2 Identity Server |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:wso2:wso2_carbon_magiclink_authenticator_module:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wso2
Wso2 wso2 Carbon Magiclink Authenticator Module Wso2 wso2 Identity Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WSO2
Published:
Updated: 2026-05-11T12:38:39.383Z
Reserved: 2025-09-15T08:51:01.163Z
Link: CVE-2025-10470
Updated: 2026-05-11T12:38:36.189Z
Status : Received
Published: 2026-05-11T12:16:10.530
Modified: 2026-05-11T12:16:10.530
Link: CVE-2025-10470
No data.
OpenCVE Enrichment
Updated: 2026-05-11T17:45:26Z