keycloak-26.6

Direct Vulnerabilities

Known vulnerabilities in the keycloak-26.6 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Resource Exhaustion

<26.6.4-r21
  • L
GHSA-c69g-56f8-xwqj

<26.6.4-r21
  • L
GHSA-93wv-jw9v-4972

<26.6.4-r21
  • M
HTTP Request Smuggling

<26.6.4-r21
  • L
GHSA-558v-64gr-wgg4

<26.6.4-r20
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<26.6.4-r20
  • L
Not Failing Securely ('Failing Open')

<26.6.4-r19
  • L
GHSA-j92g-9f8w-j867

<26.6.4-r19
  • L
GHSA-4fh9-h7wg-q85m

<26.6.4-r17
  • M
CVE-2025-66400

<26.6.4-r17
  • L
GHSA-5jmj-h7xm-6q6v

<26.6.4-r16
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<26.6.4-r16
  • L
GHSA-396q-4vc8-28x9

<26.6.4-r15
  • L
Improper Handling of Case Sensitivity

<26.6.4-r15
  • M
Open Redirect

<26.6.4-r14
  • L
GHSA-2j2x-hqr9-3h42

<26.6.4-r14
  • L
Server-Side Request Forgery (SSRF)

<26.6.4-r1
  • L
Incomplete Blacklist

<26.6.4-r1
  • L
GHSA-j3rv-43j4-c7qm

<26.6.4-r1
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<26.6.4-r1
  • L
GHSA-hgj6-7826-r7m5

<26.6.4-r1
  • L
GHSA-5hh8-q8hv-fr38

<26.6.4-r1
  • L
GHSA-rcqc-6cw3-h962

<26.6.4-r1
  • L
Incorrect Authorization

<26.6.4-r1
  • L
Incomplete Blacklist

<26.6.4-r1
  • L
GHSA-rmj7-2vxq-3g9f

<26.6.4-r1
  • L
Incorrect Authorization

<26.6.4-r1
  • L
GHSA-9fxm-vc8v-hj55

<26.6.4-r1
  • L
HTTP Request Smuggling

<26.6.3-r5
  • L
GHSA-hvcg-qmg6-jm4c

<26.6.3-r5
  • L
GHSA-w573-9ffj-6ff9

<26.6.3-r4
  • L
Information Exposure

<26.6.3-r4
  • L
Use of Insufficiently Random Values

<26.6.3-r3
  • C
Insufficient Verification of Data Authenticity

<26.6.3-r3
  • C
Insufficient Verification of Data Authenticity

<26.6.3-r3
  • L
GHSA-cc37-9q2j-3hfv

<26.6.3-r3
  • L
Improper Check or Handling of Exceptional Conditions

<26.6.3-r3
  • L
GHSA-xmv7-r254-6q78

<26.6.3-r3
  • L
GHSA-c2gf-v879-257j

<26.6.3-r3
  • L
GHSA-676x-f7gg-47vc

<26.6.3-r3
  • L
Resource Exhaustion

<26.6.3-r3
  • L
GHSA-5pvg-856g-cp85

<26.6.3-r3
  • L
GHSA-5x3r-wrvg-rp6q

<26.6.3-r3
  • H
Resource Exhaustion

<26.6.3-r3
  • L
GHSA-3qp7-7mw8-wx86

<26.6.3-r2
  • L
GHSA-x4gw-5cx5-pgmh

<26.6.3-r2
  • L
Improper Access Control

<26.6.3-r2
  • L
Allocation of Resources Without Limits or Throttling

<26.6.3-r2
  • M
Allocation of Resources Without Limits or Throttling

<26.6.1-r5
  • L
GHSA-3g76-f9xq-8vp6

<26.6.1-r5
  • H
Incorrect Authorization

<26.6.1-r5
  • L
GHSA-rc95-pcm8-65v9

<26.6.1-r5
  • L
GHSA-p93r-85wp-75v3

<26.6.1-r4
  • L
CVE-2026-5588

<26.6.1-r4
  • L
CVE-2026-5598

<26.6.1-r4
  • L
GHSA-c3fc-8qff-9hwx

<26.6.1-r4
  • L
CVE-2026-0636

<26.6.1-r4
  • L
GHSA-wg6q-6289-32hp

<26.6.1-r4
  • L
GHSA-98qh-xjc8-98pq

<26.6.1-r3
  • L
Allocation of Resources Without Limits or Throttling

<26.6.1-r3
  • L
Missing Release of Resource after Effective Lifetime

<26.6.1-r2
  • L
GHSA-45q3-82m4-75jr

<26.6.1-r2
  • L
Resource Exhaustion

<26.6.1-r2
  • L
GHSA-57rv-r2g8-2cj3

<26.6.1-r2
  • M
CVE-2026-7500

<26.6.1-r2
  • L
GHSA-rwm7-x88c-3g2p

<26.6.1-r2
  • L
GHSA-m4cv-j2px-7723

<26.6.1-r2
  • L
GHSA-hm32-hfmw-rhvg

<26.6.1-r2
  • L
GHSA-f6hv-jmp6-3vwv

<26.6.1-r2
  • C
HTTP Request Smuggling

<26.6.1-r2
  • L
Integer Overflow or Wraparound

<26.6.1-r2
  • H
HTTP Response Splitting

<26.6.1-r2
  • L
CRLF Injection

<26.6.1-r2
  • L
Resource Exhaustion

<26.6.1-r2
  • H
HTTP Request Smuggling

<26.6.1-r2
  • L
GHSA-xxqh-mfjm-7mv9

<26.6.1-r2
  • L
GHSA-cm33-6792-r9fm

<26.6.1-r2
  • L
GHSA-mj4r-2hfc-f8p6

<26.6.1-r2
  • C
HTTP Request Smuggling

<26.6.1-r2
  • L
GHSA-38f8-5428-x5cv

<26.6.1-r2
  • L
GHSA-v8h7-rr48-vmmv

<26.6.1-r2
  • C
Improper Input Validation

<26.6.1-r2