Skip to content

cosmo/keycloak 0.14.2 ships CVE-affected packages; upstream keycloak 26.7.0 has the fixes #3107

Description

@hayduke19us

The published ghcr.io/wundergraph/cosmo/keycloak:0.14.2 (built from keycloak/Dockerfile, FROM quay.io/keycloak/keycloak:26.5.6, RHEL 9.7 UBI) still ships:

CVE Package Installed Fixed
CVE-2026-22016 java-21-openjdk-headless 1:21.0.10.0.7-1.el9 1:21.0.11.0.10-2.el9
CVE-2026-34282 java-21-openjdk-headless 1:21.0.10.0.7-1.el9 1:21.0.11.0.10-2.el9
CVE-2026-4878 libcap 2.48-10.el9 2.48-10.el9_8.1

Verified 2026-07-22 against sha256:f6fd05dd57f5d07cb30384456a7329fcb94a435e14c52d9be1e2457e0d3a9764 by querying the image's rpmdb from an almalinux:9 container.

quay.io/keycloak/keycloak:26.7.0 (released 2026-07-09) already ships the fixed versions -- verified from that image's rpmdb. Bumping ARG KEYCLOAK_VERSION in keycloak/Dockerfile from 26.5.6 -> 26.7.0 and re-publishing would clear all three CVEs downstream.

Happy to open a PR with the one-line bump if that would help.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions