/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-fqc9-ghv9-w658

Published

Last updated

https://images.chainguard.dev/security/CGA-fqc9-ghv9-w658
Package

keycloak-fips-26.3

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2025-12390
  • GHSA-rg35-5v25-mqvp

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-12390

Updates

Status

Fix not planned

Impact

Keycloak 26.3.x became EOL on Sep 30, 2025 and will not be receiving this security fix from upstream. The reported fix version exists as a keycloak enterprise solution and cannot be ingested. Chainguard recommends updating to keycloak 26.4.x or later.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing