VYPR

apk package

wolfi/keycloak-26.5-iamguarded-compat

pkg:apk/wolfi/keycloak-26.5-iamguarded-compat

Vulnerabilities (23)

  • CVE-2025-14559MedJan 21, 2026
    affected < 26.5.2-r0fixed 26.5.2-r0

    A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and refresh tokens for disabled users, leading to unauthorized use of previously revoked privileges, via a business logic vulnerability in the Token Exchange implemen

  • CVE-2026-1002MedJan 15, 2026
    affected < 26.5.7-r0fixed 26.5.7-r0

    The Vert.x Web static handler component cache can be manipulated to deny the access to static files served by the handler using specifically crafted request URI. The issue comes from an improper implementation of the C. rule of section 5.2.4 of RFC3986 and is fixed in Vert.x Co

  • CVE-2025-66560MedJan 7, 2026
    affected < 26.5.1-r0fixed 26.5.1-r0

    Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3.27.2, and 3.20.5, a vulnerability exists in the HTTP layer of Quarkus REST related to response handling. When a response is being written, the framework waits f

Page 2 of 2