Status
Justification
Impact
The affected component’s suffix is non-standard for Maven parsing. It supports “.” as a delimiter, but treats jre11 as an unknown qualifier that sorts after known ones (alpha, beta, rc, ga, etc.), which breaks version matching. This vulnerability was resolved in the following PR for keycloak 26.4.2-r2: https://github.com/wolfi-dev/os/pull/71234
Status
Status
Fixed version
26.4.2-r0Status