keycloak-fips-26.5

Direct Vulnerabilities

Known vulnerabilities in the keycloak-fips-26.5 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-642r-3gj9-2pj5

<26.5.7-r14
  • L
CVE-2026-68494

<26.5.7-r14
  • L
GHSA-rcqc-6cw3-h962

<26.5.7-r14
  • L
Incorrect Authorization

<26.5.7-r14
  • L
GHSA-mhm7-754m-9p8w

<26.5.7-r14
  • L
Incomplete Blacklist

<26.5.7-r14
  • L
Incorrect Authorization

<26.5.7-r14
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<26.5.7-r14
  • L
Incorrect Authorization

<26.5.7-r14
  • L
GHSA-r7wm-3cxj-wff9

<26.5.7-r14
  • L
Server-Side Request Forgery (SSRF)

<26.5.7-r14
  • L
GHSA-9fxm-vc8v-hj55

<26.5.7-r14
  • L
GHSA-rmj7-2vxq-3g9f

<26.5.7-r14
  • L
GHSA-5gvw-p9qm-jgwh

<26.5.7-r14
  • L
GHSA-j3rv-43j4-c7qm

<26.5.7-r14
  • L
Incomplete Blacklist

<26.5.7-r14
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<26.5.7-r14
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<26.5.7-r14
  • L
GHSA-5hh8-q8hv-fr38

<26.5.7-r14
  • L
GHSA-5jmj-h7xm-6q6v

<26.5.7-r14
  • L
GHSA-3pjw-73gf-8qr5

<26.5.7-r14
  • L
GHSA-hgj6-7826-r7m5

<26.5.7-r14
  • L
Improper Verification of Cryptographic Signature

<26.5.7-r13
  • L
Improper Access Control

<26.5.7-r13
  • L
GHSA-fccg-mwvh-qqg4

<26.5.7-r13
  • L
GHSA-c4c3-7fpv-j4q5

<26.5.7-r13
  • C
Improper Check for Unusual or Exceptional Conditions

<26.5.7-r13
  • L
GHSA-3qp7-7mw8-wx86

<26.5.7-r13
  • L
GHSA-x4gw-5cx5-pgmh

<26.5.7-r13
  • H
Algorithmic Complexity

<26.5.7-r13
  • L
Allocation of Resources Without Limits or Throttling

<26.5.7-r13
  • L
GHSA-c653-97m9-rcg9

<26.5.7-r13
  • L
GHSA-4gv3-mc9p-5wqc

<26.5.7-r12
  • C
Weak Password Recovery Mechanism for Forgotten Password

<26.5.7-r12
  • L
GHSA-qxvw-fvwx-5cp7

<26.5.7-r11
  • L
Inappropriate Encoding for Output Context

<26.5.7-r11
  • L
Cleartext Transmission of Sensitive Information

<26.5.7-r11
  • L
Insufficiently Protected Credentials

<26.5.7-r11
  • L
GHSA-xvr9-35cr-46v9

<26.5.7-r11
  • L
GHSA-g9jj-cgmh-9f38

<26.5.7-r11
  • L
GHSA-8c42-7qj2-3j46

<26.5.7-r10
  • L
HTTP Request Smuggling

<26.5.7-r10
  • L
Improper Access Control

<26.5.7-r10
  • H
HTTP Request Smuggling

<26.5.7-r10
  • L
Integer Overflow or Wraparound

<26.5.7-r10
  • L
CRLF Injection

<26.5.7-r10
  • H
HTTP Request Smuggling

<26.5.7-r10
  • M
CRLF Injection

<26.5.7-r10
  • L
GHSA-v8h7-rr48-vmmv

<26.5.7-r10
  • L
Resource Exhaustion

<26.5.7-r10
  • L
GHSA-q4f6-jm68-57ww

<26.5.7-r10
  • L
GHSA-38f8-5428-x5cv

<26.5.7-r10
  • L
GHSA-mvh2-crg5-v77c

<26.5.7-r10
  • L
Resource Exhaustion

<26.5.7-r10
  • L
GHSA-57rv-r2g8-2cj3

<26.5.7-r10
  • L
GHSA-6jqx-86gh-f27w

<26.5.7-r10
  • H
Resource Exhaustion

<26.5.7-r10
  • L
GHSA-4mp9-239f-g9hg

<26.5.7-r10
  • H
Information Exposure Through Caching

<26.5.7-r10
  • C
HTTP Request Smuggling

<26.5.7-r10
  • H
Allocation of Resources Without Limits or Throttling

<26.5.7-r10
  • L
GHSA-jppx-w49h-x2qq

<26.5.7-r10
  • L
GHSA-m4cv-j2px-7723

<26.5.7-r10
  • L
GHSA-gcjf-9mgh-3p7g

<26.5.7-r10
  • C
HTTP Request Smuggling

<26.5.7-r10
  • L
GHSA-hvcg-qmg6-jm4c

<26.5.7-r10
  • L
GHSA-6cqp-g7gg-8hr5

<26.5.7-r10
  • L
GHSA-xxqh-mfjm-7mv9

<26.5.7-r10
  • H
Resource Exhaustion

<26.5.7-r6
  • L
GHSA-5x3r-wrvg-rp6q

<26.5.7-r6
  • L
GHSA-f6hv-jmp6-3vwv

<26.5.7-r10
  • L
Resource Exhaustion

<26.5.7-r10
  • L
GHSA-c2gf-v879-257j

<26.5.7-r6
  • L
GHSA-93wv-jw9v-4972

<26.5.7-r6
  • L
Resource Exhaustion

<26.5.7-r6
  • L
Resource Exhaustion

<26.5.7-r6
  • M
HTTP Request Smuggling

<26.5.7-r6
  • M
Allocation of Resources Without Limits or Throttling

<26.5.7-r6
  • L
GHSA-c69g-56f8-xwqj

<26.5.7-r6
  • L
GHSA-563q-j3cm-6jxm

<26.5.7-r6
  • L
GHSA-558v-64gr-wgg4

<26.5.7-r5
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<26.5.7-r5
  • L
Resource Exhaustion

<26.5.7-r5
  • L
GHSA-mj4r-2hfc-f8p6

<26.5.7-r5
  • L
GHSA-98qh-xjc8-98pq

<26.5.7-r4
  • L
Allocation of Resources Without Limits or Throttling

<26.5.7-r4
  • L
GHSA-j92g-9f8w-j867

<26.5.7-r4
  • L
Not Failing Securely ('Failing Open')

<26.5.7-r4
  • L
GHSA-rwm7-x88c-3g2p

<26.5.7-r0
  • L
Missing Release of Resource after Effective Lifetime

<26.5.7-r0
  • M
HTTP Request Smuggling

<26.5.7-r0
  • L
GHSA-cphf-4846-3xx9

<26.5.7-r0
  • L
GHSA-gv3v-2cpp-3pmq

<26.5.6-r4
  • M
Improper Output Neutralization for Logs

<26.5.6-r4
  • L
GHSA-22rm-wp4x-v5cx

<26.5.6-r4
  • L
GHSA-rhgq-f8x5-j2jc

<26.5.6-r4
  • H
Excessive Platform Resource Consumption within a Loop

<26.5.6-r4
  • L
GHSA-h4wv-g838-66g3

<26.5.6-r4
  • L
GHSA-cjm2-j6cm-6p6m

<26.5.6-r4
  • L
GHSA-4pgc-gfrr-wcmg

<26.5.6-r4
  • M
Improper Access Control

<26.5.6-r4
  • L
Information Exposure

<26.5.6-r4
  • H
Insufficient Compartmentalization

<26.5.6-r4
  • H
Open Redirect

<26.5.6-r4
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<26.5.6-r4
  • L
GHSA-hj93-h7pg-fh6v

<26.5.6-r4
  • L
GHSA-f2hx-5fx3-hmcv

<26.5.6-r4
  • M
Insufficient Compartmentalization

<26.5.6-r4
  • L
Server-Side Request Forgery (SSRF)

<26.5.6-r4
  • L
GHSA-rx66-hj7g-28h7

<26.5.6-r4
  • L
GHSA-pwqr-wmgm-9rr8

<26.5.6-r2
  • L
GHSA-w9fj-cfpg-grvv

<26.5.6-r3
  • L
HTTP Request Smuggling

<26.5.6-r2
  • H
Allocation of Resources Without Limits or Throttling

<26.5.6-r3
  • L
GHSA-8g9r-9wjw-37j4

<26.5.6-r0
  • M
Improper Access Control

<26.5.6-r0
  • L
GHSA-xh32-c9wx-phrp

<26.5.6-r0
  • L
CVE-2026-3911

<26.5.6-r0
  • L
Improper Authorization

<26.5.4-r0
  • L
GHSA-fjf4-6f34-w64q

<26.5.4-r0
  • L
Missing XML Validation

<26.5.3-r0
  • L
GHSA-63v5-26vq-m4vm

<26.5.3-r0
  • L
GHSA-wv3h-x6c4-r867

<26.5.2-r0
  • M
Business Logic Errors

<26.5.2-r0
  • H
Allocation of Resources Without Limits or Throttling

<26.5.2-r0
  • L
GHSA-5rfx-cp42-p624

<26.5.2-r0