keycloak-26.3
Chainguard
Status
Impact
Vulnerable vertx-web version 4.5.14 is being pulled in through quarkus-vertx-http dependency. Latest available quarkus-vertx-http version 3.29 still depends on a vulnerable vertx-web version 4.5.21. Upgrading vertx-web to 4.5.22 causes test failures. Upstream will have to upgrade quarkus-vertx-http to a version that doesn't pull vertx-web 4.5.21.
Status