/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-wjmh-pg5m-8f26

Published

Last updated

https://images.chainguard.dev/security/CGA-wjmh-pg5m-8f26
Package

keycloak-26.3

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-48924
  • GHSA-j288-q9x7-2f5v

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-48924

Updates

Status

Pending upstream fix

Impact

Keycloak currently depends on quarkus v3.20.2.1, which in turn depends on the affected version of commons-lang3. Quarkus have fixed the vulnerability in v3.35.4, but have yet to backport it to the v3.20 stream. Attempts to force the upgrade of commons-lang3 to the fixed version result in build failures. Attempts to upgrade Keycloak to the v3.35 version stream of Quarkus (with the fix), also result in build failures. Pending upstream fix, specifically for Quarkus to create a v3.20 patch release, or for Keycloak to do the refactor needed for upgrading to Quarkus v3.35.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing