keycloak-fips-26.7

Direct Vulnerabilities

Known vulnerabilities in the keycloak-fips-26.7 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-68494

<26.7.0-r5
  • L
GHSA-642r-3gj9-2pj5

<26.7.0-r5
  • L
GHSA-8jcv-3c3x-vwg4

<26.7.4-r3
  • L
CVE-2026-59296

<26.7.4-r3
  • L
GHSA-q4xh-88c3-wmh7

<26.7.4-r3
  • C
CVE-2026-58062

<26.7.4-r1
  • M
HTTP Request Smuggling

<26.7.4-r3
  • L
Resource Exhaustion

<26.7.4-r5
  • L
CVE-2026-83557

<26.7.4-r3
  • L
CVE-2026-68497

<26.7.4-r3
  • H
Null Byte Interaction Error (Poison Null Byte)

<26.7.4-r3
  • L
GHSA-gx83-3vf8-gh7j

<26.7.4-r3
  • L
GHSA-77qf-r755-9gcw

<26.7.4-r3
  • L
GHSA-wjgm-6hv5-3cvf

<26.7.4-r3
  • L
GHSA-jmpc-xv4r-m7fw

<26.7.4-r3
  • L
CVE-2026-59295

<26.7.4-r3
  • L
GHSA-q86x-4w7f-8hrm

<26.7.4-r5
  • L
GHSA-h79m-h3j4-r7qm

<26.7.4-r5
  • H
Improper Handling of Alternate Encoding

<26.7.4-r5
  • L
GHSA-v7hr-hgg3-vv6q

<26.7.4-r3
  • L
CVE-2026-19032

<26.7.4-r3
  • L
GHSA-j295-77c3-9frf

<26.7.4-r1
  • L
Directory Traversal

<26.7.4-r3
  • L
GHSA-27j2-h3m2-8237

<26.7.4-r3
  • C
CVE-2026-8763

<26.7.4-r1
  • L
GHSA-qp49-qgx5-5m26

<26.7.4-r1
  • L
GHSA-v6w3-qrh8-qccc

<26.7.4-r1
  • L
CVE-2026-8798

<26.7.4-r1
  • L
CVE-2026-13505

<26.7.4-r1
  • L
GHSA-9pwp-9qqc-pr26

<26.7.4-r1
  • H
CVE-2026-13506

<26.7.4-r1
  • L
GHSA-98j2-6v39-78w8

<26.7.4-r1
  • L
GHSA-c4c3-7fpv-j4q5

<26.7.3-r1
  • C
Improper Check for Unusual or Exceptional Conditions

<26.7.3-r1
  • H
Algorithmic Complexity

<26.7.3-r1
  • L
GHSA-fccg-mwvh-qqg4

<26.7.3-r1
  • L
GHSA-qxvw-fvwx-5cp7

<26.7.2-r1
  • L
Inappropriate Encoding for Output Context

<26.7.2-r1
  • L
Insufficiently Protected Credentials

<26.7.2-r1
  • L
GHSA-g9jj-cgmh-9f38

<26.7.2-r1
  • L
GHSA-xvr9-35cr-46v9

<26.7.2-r1
  • L
Cleartext Transmission of Sensitive Information

<26.7.2-r1
  • H
Information Exposure Through Caching

<26.7.1-r4
  • L
GHSA-8c42-7qj2-3j46

<26.7.1-r4
  • H
Missing Release of Resource after Effective Lifetime

<26.7.0-r6
  • L
CVE-2026-40983

<26.7.1-r1
  • L
GHSA-g3pr-3p32-fp23

<26.7.1-r1
  • L
CVE-2026-40984

<26.7.1-r1
  • L
GHSA-w737-wx49-qj23

<26.7.1-r1
  • L
Improper Authentication

<26.7.0-r7
  • L
GHSA-qcxp-gm7m-4j5v

<26.7.0-r7
  • L
GHSA-mfg7-5gfp-c4w3

<26.7.0-r6
  • L
CRLF Injection

<26.7.0-r5
  • H
Resource Exhaustion

<26.7.0-r5
  • L
GHSA-c69g-56f8-xwqj

<26.7.0-r5
  • M
HTTP Request Smuggling

<26.7.0-r5
  • L
GHSA-r7wm-3cxj-wff9

<26.7.0-r5
  • L
GHSA-q6cq-mhr2-jmr5

<26.7.0-r5
  • L
GHSA-wh89-7897-x99h

<26.7.0-r5
  • L
GHSA-mvh2-crg5-v77c

<26.7.0-r3
  • L
GHSA-jppx-w49h-x2qq

<26.7.0-r3
  • L
Resource Exhaustion

<26.7.0-r3
  • L
GHSA-gcjf-9mgh-3p7g

<26.7.0-r3
  • L
GHSA-6jqx-86gh-f27w

<26.7.0-r3
  • L
Resource Exhaustion

<26.7.0-r3
  • L
GHSA-q4f6-jm68-57ww

<26.7.0-r3
  • L
Improper Access Control

<26.7.0-r3
  • L
GHSA-4mp9-239f-g9hg

<26.7.0-r3
  • H
Allocation of Resources Without Limits or Throttling

<26.7.0-r3
  • M
CRLF Injection

<26.7.0-r3
  • L
GHSA-6cqp-g7gg-8hr5

<26.7.0-r3
  • H
Resource Exhaustion

<26.7.0-r3
  • H
HTTP Request Smuggling

<26.7.0-r3
  • L
GHSA-558v-64gr-wgg4

<26.7.0-r2
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<26.7.0-r2
  • L
GHSA-j92g-9f8w-j867

<26.7.0-r1
  • L
Not Failing Securely ('Failing Open')

<26.7.0-r1