CVE-2025-66033 MEDIUM

CVE-2025-66033: Improper Memory Cleanup in the Okta Java SDK

Vendor Okta
Product okta-sdk-java
Weakness CWE-401
Published December 10, 2025
Last update December 11, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

Description

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1.

Key dates

Disclosure timeline

December 10, 2025 CVE published
December 11, 2025 Record updated