Keycloak 26.3 depends on Quarkus v3.20.2.1, which includes the vulnerable commons-lang3 3.17.0.
The fix exists in commons-lang3 v3.18.0, but:
- Forcing commons-lang3 upgrade in the current Quarkus version results in build failures
- Upgrading to Quarkus v3.35.4 (which includes the fix) also causes build failures
Waiting for either a Quarkus v3.20 backport or Keycloak's compatibility with Quarkus v3.35+