Report: CVE-2025-10470 - Denial-of-Service via Magic Link Authentication in WSO2 Identity Server Allows S
CVE ID :CVE-2025-10470 Published : May 11, 2026, 12:16 p.m. | 34 minutes ago Description :The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. This vulnerability can result in a denial-of-service condition, causing service unavailability for deployments that utilize the Magic Link authenticator. The impact is limited to these specific deployments and requires repeated invalid authentication attempts to trigger. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...