Package
keycloak-26.4
Component
owasp-java-html-sanitizer
Latest update
Fixed version
26.4.7-r3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
26.4.7-r3Status
Impact
Keycloak 26.4.8 has been tagged upstream to address this vulnerability, but the required Maven artifacts have not yet been published to Maven Central. The Wolfi build process requires all dependency artifacts to be available in public Maven repositories. Until upstream maintainers publish the complete set of Maven artifacts for version 26.4.8 to Maven Central, this vulnerability cannot be remediated through a version update.
Status