This vulnerability can result in a denial-of-service condition, causing service unavailability for deployments that utilize the Magic Link authenticator. The impact is limited to these specific deployments and requires repeated invalid authentication attempts to trigger.
Project Subscriptions
No advisories yet.
Solution
Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4469/#solution
Workaround
No workaround given by the vendor.
Mon, 11 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. This vulnerability can result in a denial-of-service condition, causing service unavailability for deployments that utilize the Magic Link authenticator. The impact is limited to these specific deployments and requires repeated invalid authentication attempts to trigger. | |
| Title | Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows Service Unavailability | |
| First Time appeared |
Wso2
Wso2 wso2 Carbon Magiclink Authenticator Module Wso2 wso2 Identity Server |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:wso2:wso2_carbon_magiclink_authenticator_module:*:*:*:*:*:*:*:* cpe:2.3:a:wso2:wso2_identity_server:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wso2
Wso2 wso2 Carbon Magiclink Authenticator Module Wso2 wso2 Identity Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WSO2
Published:
Updated: 2026-05-11T12:38:39.383Z
Reserved: 2025-09-15T08:51:01.163Z
Link: CVE-2025-10470
Updated: 2026-05-11T12:38:36.189Z
Status : Received
Published: 2026-05-11T12:16:10.530
Modified: 2026-05-11T12:16:10.530
Link: CVE-2025-10470
No data.
OpenCVE Enrichment
Updated: 2026-05-11T17:45:26Z