Package
keycloak-26.5-iamguarded-compat
Component
jackson-core
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
Keycloak and Quarkus do not use the async JSON parser from Vert.x which is the vulnerable code path in jackson-core. Confirmed by Quarkus developer @cescoffier and keycloak maintainers in https://github.com/keycloak/keycloak/issues/46757 (closed 2026-03-03). The GHSA specifically describes a vulnerability in the async parser (JsonParserImpl) which is not exercised by keycloak's use of jackson-core.
Status