The published ghcr.io/wundergraph/cosmo/keycloak:0.14.2 (built from keycloak/Dockerfile, FROM quay.io/keycloak/keycloak:26.5.6, RHEL 9.7 UBI) still ships:
| CVE |
Package |
Installed |
Fixed |
| CVE-2026-22016 |
java-21-openjdk-headless |
1:21.0.10.0.7-1.el9 |
1:21.0.11.0.10-2.el9 |
| CVE-2026-34282 |
java-21-openjdk-headless |
1:21.0.10.0.7-1.el9 |
1:21.0.11.0.10-2.el9 |
| CVE-2026-4878 |
libcap |
2.48-10.el9 |
2.48-10.el9_8.1 |
Verified 2026-07-22 against sha256:f6fd05dd57f5d07cb30384456a7329fcb94a435e14c52d9be1e2457e0d3a9764 by querying the image's rpmdb from an almalinux:9 container.
quay.io/keycloak/keycloak:26.7.0 (released 2026-07-09) already ships the fixed versions -- verified from that image's rpmdb. Bumping ARG KEYCLOAK_VERSION in keycloak/Dockerfile from 26.5.6 -> 26.7.0 and re-publishing would clear all three CVEs downstream.
Happy to open a PR with the one-line bump if that would help.
The published
ghcr.io/wundergraph/cosmo/keycloak:0.14.2(built fromkeycloak/Dockerfile,FROM quay.io/keycloak/keycloak:26.5.6, RHEL 9.7 UBI) still ships:Verified 2026-07-22 against
sha256:f6fd05dd57f5d07cb30384456a7329fcb94a435e14c52d9be1e2457e0d3a9764by querying the image's rpmdb from analmalinux:9container.quay.io/keycloak/keycloak:26.7.0(released 2026-07-09) already ships the fixed versions -- verified from that image's rpmdb. BumpingARG KEYCLOAK_VERSIONinkeycloak/Dockerfilefrom26.5.6->26.7.0and re-publishing would clear all three CVEs downstream.Happy to open a PR with the one-line bump if that would help.