← All images

keycloak

14 open findings · 14 with upstream fix available

Image: ghcr.io/rtvkiz/minimal-keycloak:latest  ·  Size: 398 MB  ·  Last rebuilt: 0d ago  ·  Updated: 2026-06-17 21:45 UTC

PackageVersionSeverityCVEFixDescriptionVEX
netty-codec-haproxy4.1.133.FinalHIGHGHSA-h2qv-fj59-j46j4.1.135.FinalNetty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
netty-handler4.1.133.FinalHIGHGHSA-x4gw-5cx5-pgmh4.1.135.FinalNetty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
netty-codec-haproxy4.1.133.FinalHIGHGHSA-cc37-9q2j-3hfv4.1.135.FinalNetty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
netty-handler4.1.133.FinalHIGHGHSA-3qp7-7mw8-wx864.1.135.FinalNetty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
netty-resolver-dns4.1.133.FinalHIGHGHSA-5pvg-856g-cp854.1.135.FinalNetty has Insufficient Bailiwick Validation for NS Records
netty-resolver-dns4.1.133.FinalHIGHGHSA-676x-f7gg-47vc4.1.135.FinalNetty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
netty-handler4.1.133.FinalHIGHGHSA-c653-97m9-rcg94.1.135.FinalNetty: Wrapping plain trust manager silently disables hostname verification
netty-codec-http24.1.133.FinalMEDIUMGHSA-c2gf-v879-257j4.1.135.Finalnetty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
netty-codec-http24.1.133.FinalMEDIUMGHSA-5x3r-wrvg-rp6q4.1.135.FinalNetty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
netty-resolver-dns4.1.133.FinalMEDIUMGHSA-xmv7-r254-6q784.1.135.FinalNetty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
netty-codec-http24.1.133.FinalMEDIUMGHSA-563q-j3cm-6jxm4.1.135.FinalNetty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
netty-codec-http4.1.133.FinalMEDIUMGHSA-hvcg-qmg6-jm4c4.1.135.FinalNetty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted
netty-transport-native-epoll4.1.133.FinalMEDIUMGHSA-w573-9ffj-6ff94.1.135.FinalNetty: Unix-socket fd receive leaks descriptors when peer sends two at once
netty-transport-native-epoll4.1.133.FinalMEDIUMGHSA-w573-9ffj-6ff94.1.135.FinalNetty: Unix-socket fd receive leaks descriptors when peer sends two at once