/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-5h6x-m8wc-r27v

Published

Last updated

https://images.chainguard.dev/security/CGA-5h6x-m8wc-r27v
Package

keycloak-21.1

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2025-8419
  • GHSA-qj5r-2r5p-phc7

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-8419

Updates

Status

Fix not planned

Impact

This vulnerability affects keycloak-services 21.1.2, which is a self-contained component built from the same source repository as the package. The vulnerability is inherent to Keycloak version 21.1.2 and cannot be fixed through dependency updates. Keycloak 21.1.2 reached its end-of-life on July 11, 2023. GitHub Advisory API indicates no patched version is available (firstPatchedVersion: null). Customers should migrate to supported Keycloak versions (26.x series) to address this and other security vulnerabilities.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing