/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-g3qr-2mj4-4x8j

Published

Last updated

https://images.chainguard.dev/security/CGA-g3qr-2mj4-4x8j
Package

keycloak-26.4

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2025-59250
  • GHSA-m494-w24q-6f7w

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-59250

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

The affected component’s suffix is non-standard for Maven parsing. It supports “.” as a delimiter, but treats jre11 as an unknown qualifier that sorts after known ones (alpha, beta, rc, ga, etc.), which breaks version matching. This vulnerability was resolved in the following PR for keycloak 26.4.2-r2: https://github.com/wolfi-dev/os/pull/71234

Status

Under investigation

Status

Fixed

Fixed version

26.4.2-r0

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing