CVE-2025-10470 - CVE House
Back to Database
Status published High CVE-2025-10470

Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Unavailability

Vulnerability Description

The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. This vulnerability can result in a denial-of-service condition, causing service unavailability for deployments that utilize the Magic Link authenticator. The impact is limited to these specific deployments and requires repeated invalid authentication attempts to trigger.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-10470

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

WSO2 Identity Server, WSO2 Carbon MagicLink Authenticator Module
Vulnerable Versions:
7.0.0, 1.1.22, 1.1.31

Timeline

Official Publish: May 11th, 2026
Last Modified: May 11th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Weaknesses (CWE)