ghcr.io/wundergraph/cosmo/keycloak:0.16.0 (current latest, digest sha256:707bb1d0291714fa523b41dd18275465ee4cb09b4b8bcbb78c640fae902aebae) bundles org.bouncycastle:bcprov-jdk18on 1.84, which is affected by 25 CVEs (4 critical, 21 high). The image pins KEYCLOAK_VERSION=26.7.2 in keycloak/Dockerfile, which resolves bcprov 1.84 via the Quarkus 3.33.3.1 BOM. Upstream Keycloak 26.7.5 uses the Quarkus 3.33.4 BOM and ships bcprov 1.86, which clears all of them.
Verified 2026-09-30 against sha256:707bb1d0291714fa523b41dd18275465ee4cb09b4b8bcbb78c640fae902aebae by inspecting the image contents: /opt/keycloak/lib/lib/main/org.bouncycastle.bcprov-jdk18on-1.84.jar and /opt/keycloak/bin/client/lib/bcprov-jdk18on-1.84.jar. The same inspection of quay.io/keycloak/keycloak:26.7.5 shows bcprov-jdk18on-1.86.jar in both locations. BOM sources: quarkus-bom 3.33.3.1 -> bcprov 1.84, quarkus-bom 3.33.4 -> bcprov 1.86 (Maven Central).
The fix would land in keycloak/Dockerfile by bumping ARG KEYCLOAK_VERSION from 26.7.2 to 26.7.5. This follows the same pattern as #3107.
Happy to open a PR with this one-line change if useful.
This affects us in production (Zendesk runs a large deployment on Cosmo), and the critical SLA is already breached on our side, so we are keen to help get this in.
ghcr.io/wundergraph/cosmo/keycloak:0.16.0(currentlatest, digestsha256:707bb1d0291714fa523b41dd18275465ee4cb09b4b8bcbb78c640fae902aebae) bundlesorg.bouncycastle:bcprov-jdk18on 1.84, which is affected by 25 CVEs (4 critical, 21 high). The image pinsKEYCLOAK_VERSION=26.7.2inkeycloak/Dockerfile, which resolves bcprov 1.84 via the Quarkus 3.33.3.1 BOM. Upstream Keycloak 26.7.5 uses the Quarkus 3.33.4 BOM and ships bcprov 1.86, which clears all of them.Verified 2026-09-30 against
sha256:707bb1d0291714fa523b41dd18275465ee4cb09b4b8bcbb78c640fae902aebaeby inspecting the image contents:/opt/keycloak/lib/lib/main/org.bouncycastle.bcprov-jdk18on-1.84.jarand/opt/keycloak/bin/client/lib/bcprov-jdk18on-1.84.jar. The same inspection ofquay.io/keycloak/keycloak:26.7.5showsbcprov-jdk18on-1.86.jarin both locations. BOM sources: quarkus-bom 3.33.3.1 -> bcprov 1.84, quarkus-bom 3.33.4 -> bcprov 1.86 (Maven Central).The fix would land in
keycloak/Dockerfileby bumpingARG KEYCLOAK_VERSIONfrom26.7.2to26.7.5. This follows the same pattern as #3107.Happy to open a PR with this one-line change if useful.
This affects us in production (Zendesk runs a large deployment on Cosmo), and the critical SLA is already breached on our side, so we are keen to help get this in.