keycloak-26.2
Chainguard
Status
Impact
Vulnerable vertx-web version 4.5.14 is being pulled in through quarkus-vertx-http dependency. Latest available quarkus-vertx-http version 3.29 still depends on a vulnerable vertx-web version 4.5.21. Upgrading vertx-web to 4.5.22 causes build failures. This package is no longer supported upstream and has reached its end of life as a result won't receive a fix upstream.
Status