A AegiFlow
HIGHCVSS 8.4EPSS 0.2%

CVE-2025-67505

Race condition in the Okta Java SDK

Published
2025-12-10
Modified
2026-09-15
EPSS percentile
11%
Aliases
GHSA-j5gq-897m-2rff
Sources
github-advisory

Summary

### Description In the Okta Java SDK, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. ### Affected product and versions You may be affected if you meet the following preconditions: - Using the Okta Java SDK between versions 11.0.0 and 20.0.0, and - Implementing a multithreaded application with the ApiClient class where the response status code is used in access control flows ### Resolution Upgrade Okta/okta-sdk-java to versions 21.0.0 or greater.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavencom.okta.sdk:okta-sdk-root20.0.1

Remediation: Upgrade to 20.0.1 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.