CVE-2025-66033
Last modified
CVE-2025-66033 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, specific multithreaded implementations may encounter memory issues as threads are not properly cleaned up after requests are completed. Over time, this can degrade performance and availability in long-running applications and may result in a denial-of-service condition under sustained load. In addition to using the affected versions, users may be at risk if they are implementing a long-running application using the ApiClient in a multi-threaded manner. This issue is fixed in version 24.0.1.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Okta | Java Management Sdk | >= 21.0.0, < 24.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-66033?
How severe is CVE-2025-66033?
How do I fix CVE-2025-66033?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-66028OneUptime is a solution for monitoring and managing online s…8.2
- CVE-2025-66029Open OnDemand provides remote web access to supercomputers. …7.6
- CVE-2025-6603A vulnerability was found in coldfunction qCUDA up to db0085…5.3
- CVE-2025-66030Forge (also called `node-forge`) is a native implementation …5.3
- CVE-2025-66031Forge (also called `node-forge`) is a native implementation …7.5
- CVE-2025-66032Claude Code is an agentic coding tool. Prior to 1.0.93, Due …9.8
- CVE-2025-66034fontTools is a library for manipulating fonts, written in Py…9.8
- CVE-2025-66035Angular is a development platform for building mobile and de…7.7
- CVE-2025-66036Retro is an online platform providing items of vintage colle…6.1
- CVE-2025-66037OpenSC is an open source smart card tools and middleware. Pr…6.8
- CVE-2025-66038OpenSC is an open source smart card tools and middleware. Pr…6.8
- CVE-2025-66039FreePBX Endpoint Manager is a module for managing telephony …9.8
Are you affected by CVE-2025-66033?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
