VYPR

apk package

chainguard/keycloak-26.5-iamguarded-compat

pkg:apk/chainguard/keycloak-26.5-iamguarded-compat

Vulnerabilities (23)

  • CVE-2026-55858MedAug 28, 2026
    affected < 26.5.7-r5fixed 26.5.7-r5

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side escaping under the assumption that the connection character set

  • CVE-2026-55857MedAug 28, 2026
    affected < 26.5.7-r5fixed 26.5.7-r5

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insecure connection. The mysql_clear_password pl

  • CVE-2026-55856MedAug 28, 2026
    affected < 26.5.7-r5fixed 26.5.7-r5

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a password, and does not configure serverSslCer

  • CVE-2026-18401MedAug 4, 2026
    affected < 0fixed 0

    The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of a

  • CVE-2026-53669MedJul 27, 2026
    affected < 26.5.7-r3fixed 26.5.7-r3

    React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0.

  • CVE-2026-53666MedJul 27, 2026
    affected < 26.5.7-r3fixed 26.5.7-r3

    React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected construc

  • CVE-2026-40181MedJun 2, 2026
    affected < 26.5.7-r3fixed 26.5.7-r3

    React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger an open redirect to an external domain due to path values starting with // being reinterpreted as protocol-relative URLs. The le

  • CVE-2026-42577HigMay 13, 2026
    affected < 26.5.7-r1fixed 26.5.7-r1

    Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP connections that receive a RST after being half-closed, leading to stale channels that are never cleaned up and, in some

  • CVE-2026-4636HigApr 2, 2026
    affected < 26.5.7-r0fixed 26.5.7-r0

    A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an a

  • CVE-2026-4634HigApr 2, 2026
    affected < 26.5.7-r0fixed 26.5.7-r0

    A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged process

  • CVE-2026-4325MedApr 2, 2026
    affected < 26.5.7-r0fixed 26.5.7-r0

    A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed action tokens, such as password re

  • CVE-2026-4282HigApr 2, 2026
    affected < 26.5.7-r0fixed 26.5.7-r0

    A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable ac

  • CVE-2026-3872HigApr 2, 2026
    affected < 26.5.7-r0fixed 26.5.7-r0

    A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting i

  • CVE-2026-33871HigMar 27, 2026
    affected < 26.5.6-r3fixed 26.5.6-r3

    Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit o

  • CVE-2026-33870HigMar 27, 2026
    affected < 26.5.6-r2fixed 26.5.6-r2

    Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final an

  • CVE-2026-4633LowMar 23, 2026
    affected < 26.5.7-r0fixed 26.5.7-r0

    A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to determine the existence of users, leading to information disclosure through user e

  • CVE-2026-3429MedMar 11, 2026
    affected < 26.5.6-r0fixed 26.5.6-r0

    A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obtained a victim’s password can delete the vic

  • CVE-2026-3911LowMar 11, 2026
    affected < 26.5.6-r0fixed 26.5.6-r0

    A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This u

  • CVE-2025-11537MedFeb 10, 2026
    affected < 26.5.6-r3fixed 26.5.6-r3

    A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log f

  • CVE-2026-1190LowJan 26, 2026
    affected < 26.5.3-r0fixed 26.5.3-r0

    A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationData`. This allows an attacker to delay the

Page 1 of 2