/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-5h6x-m8wc-r27v

Published

Last updated

https://images.chainguard.dev/security/CGA-5h6x-m8wc-r27v
Package

keycloak-21.1

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2025-8419
  • GHSA-qj5r-2r5p-phc7

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-8419

Updates

Status

Fix not planned

Impact

This vulnerability affects keycloak-services 21.1.2, which is a self-contained component built from the same source repository as the package. The vulnerability is inherent to Keycloak version 21.1.2 and cannot be fixed through dependency updates. Keycloak 21.1.2 reached its end-of-life on July 11, 2023. GitHub Advisory API indicates no patched version is available (firstPatchedVersion: null). Customers should migrate to supported Keycloak versions (26.x series) to address this and other security vulnerabilities.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing