apk package
chainguard/keycloak-fips-26.7-operator
pkg:apk/chainguard/keycloak-fips-26.7-operator
Vulnerabilities (7)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-56746 | — | < 26.7.0-r3 | 26.7.0-r3 | Jul 23, 2026 | Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortC | ||
| CVE-2026-55833 | — | < 26.7.0-r3 | 26.7.0-r3 | Jul 21, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the | ||
| CVE-2026-55831 | — | < 26.7.0-r3 | 26.7.0-r3 | Jul 21, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting | ||
| CVE-2026-59921 | mod | 5.7 | < 26.7.0-r3 | 26.7.0-r3 | Jul 9, 2026 | io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder | |
| CVE-2026-59919 | mod | 5.5 | < 26.7.0-r5 | 26.7.0-r5 | Jul 9, 2026 | io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy | |
| CVE-2026-59900 | mod | 6.5 | < 26.7.0-r5 | 26.7.0-r5 | Jul 9, 2026 | io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2 | |
| CVE-2026-59899 | imp | 7.5 | < 26.7.0-r3 | 26.7.0-r3 | Jul 9, 2026 | io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) |
- CVE-2026-56746Jul 23, 2026affected < 26.7.0-r3fixed 26.7.0-r3
Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortC
- CVE-2026-55833Jul 21, 2026affected < 26.7.0-r3fixed 26.7.0-r3
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the
- CVE-2026-55831Jul 21, 2026affected < 26.7.0-r3fixed 26.7.0-r3
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting
- affected < 26.7.0-r3fixed 26.7.0-r3
io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
- affected < 26.7.0-r5fixed 26.7.0-r5
io.netty/netty-codec-haproxy: Netty: Improper CR/LF neutralization in netty-codec-haproxy
- affected < 26.7.0-r5fixed 26.7.0-r5
io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
- affected < 26.7.0-r3fixed 26.7.0-r3
io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)