VYPR

apk package

chainguard/keycloak-26.7

pkg:apk/chainguard/keycloak-26.7

Vulnerabilities (8)

  • CVE-2026-56746Jul 23, 2026
    affected < 26.7.0-r4fixed 26.7.0-r4

    Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortC

  • CVE-2026-55833Jul 21, 2026
    affected < 26.7.0-r4fixed 26.7.0-r4

    Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the

  • CVE-2026-55831Jul 21, 2026
    affected < 26.7.0-r4fixed 26.7.0-r4

    Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting

  • CVE-2026-59921modJul 9, 2026
    affected < 26.7.0-r4fixed 26.7.0-r4

    io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

  • CVE-2026-59919modJul 9, 2026
    affected < 26.7.0-r5fixed 26.7.0-r5

    io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy

  • CVE-2026-59899impJul 9, 2026
    affected < 26.7.0-r4fixed 26.7.0-r4

    io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)

  • CVE-2026-54515medJun 23, 2026
    affected < 26.7.0-r1fixed 26.7.0-r1

    ## Summary In `BeanDeserializerBase.createContextual()`, per-property `@JsonIgnoreProperties` exclusions are applied by `_handleByNameInclusion()`, producing a `contextual` deserializer whose `BeanPropertyMap` has the ignored properties removed. The subsequent per-property case-i

  • CVE-2017-12159HigOct 26, 2017
    affected < 0fixed 0

    It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.