/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-j5q9-2mcv-73gp

Published

Last updated

https://images.chainguard.dev/security/CGA-j5q9-2mcv-73gp
Package

keycloak-26.2

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2025-10939
  • GHSA-c6cm-5gc7-c3f4

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-10939

Updates

Status

Fix not planned

Impact

Keycloak 26.2.x became EOL on May 28, 2025 and will not be receiving this security fix from upstream. The reported fix version exists as a keycloak enterprise solution and cannot be ingested. Chainguard recommends updating to keycloak 26.4.x or later.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing