keycloak-fips
Chainguard
Status
Impact
Vulnerability affects quarkus-vertx 3.20.1 with no patch available for this version. Fix requires upgrading to Quarkus 3.24.0+ which introduces Hibernate 7.x dependencies. Keycloak 26.2.5 is incompatible with Hibernate 7.x API changes including moved classes like PersistenceXmlParser. Upstream maintainers must implement Hibernate 7.x compatibility and release new Keycloak version with Quarkus 3.24.x support.
Status