Skip to content

[GHSA-4gv3-mc9p-5wqc] A flaw was found in the reset-credentials flow of the... - #9208

Open
greiffmode wants to merge 1 commit into
greiffmode/advisory-improvement-9208from
greiffmode-GHSA-4gv3-mc9p-5wqc
Open

[GHSA-4gv3-mc9p-5wqc] A flaw was found in the reset-credentials flow of the...#9208
greiffmode wants to merge 1 commit into
greiffmode/advisory-improvement-9208from
greiffmode-GHSA-4gv3-mc9p-5wqc

Conversation

@greiffmode

Copy link
Copy Markdown

Updates

  • Affected products
  • References
  • Source code location
  • Summary

Comments
The advisory currently has no affected package or version metadata, although the vulnerability affects the Maven component org.keycloak:keycloak-services.

The Keycloak project tracks CVE-2026-18963 in issue #51833 and identifies 26.7.2 as a fixed release. The official Keycloak 26.7.2 release notes list the issue under security fixes.

The missing Maven metadata causes vulnerability scanners consuming the GitHub Advisory Database to produce a false negative. This was reproduced with quay.io/keycloak/keycloak:26.7.0 and Trivy 0.74.0 using a freshly downloaded
vulnerability database. Trivy correctly identified:

pkg:maven/org.keycloak/keycloak-services@26.7.0

but did not report CVE-2026-18963 because the advisory currently contains no
affected package or version range.

Supporting references:
keycloak/keycloak#51833
keycloak/keycloak#51844
https://www.keycloak.org/2026/08/keycloak-2672-released

@github-actions
github-actions Bot changed the base branch from main to greiffmode/advisory-improvement-9208 August 26, 2026 07:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant