Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CLEANSTART-2026-KC06018
  • CleanStart/keycloak
Security fixes for CVE-2017-12158, CVE-2017-12159, ghsa-3p8m-j85q-pgmj, ghsa-45p5-v273-3qqr, ghsa-4cx2-fc23-5wg6, ghsa-5rfx-cp42-p624, ghsa-72hv-8253-57qq, ghsa-84h7-rjj3-6jx4, ghsa-9342-92gg-6v29, ghsa-cbdj-484d-3x9q, ghsa-fghv-69vj-qj49, ghsa-h5fg-jpgr-rv9c, ghsa-hq9p-pm7w-8p54, ghsa-j288-q9x7-2f5v, ghsa-pwqr-wmgm-9rr8, ghsa-w9fj-cfpg-grvv applied in versions: 26.1.4-r1, 26.5.0-r0, 26.5.0-r1, 26.5.0-r2, 26.5.6-r3 6 days ago
  • Fix available
MINI-jp94-29cx-2g33
  • MinimOS/kafka-strimzi-compat-0.50
  • MinimOS/kafka_exporter-strimzi-compat-0.50
  • MinimOS/prometheus-jmx-exporter-strimzi-compat-0.50
  • MinimOS/strimzi-kafka-operator-0.50
  • MinimOS/strimzi-kafka-operator-0.50-cluster-operator
  • ... 8 more
See record for full details 16 Mar
  • No fix available
CLEANSTART-2026-SG80587
  • CleanStart/keycloak
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session 30 Jan
  • Fix available
  • Severity - 9.8 (Critical)
MINI-vfcm-rqg3-fvqw
  • MinimOS/kafka-strimzi-compat-0.45
  • MinimOS/kafka_exporter-strimzi-compat-0.45
  • MinimOS/strimzi-kafka-operator-0.45
  • MinimOS/strimzi-kafka-operator-0.45-cluster-operator
  • MinimOS/strimzi-kafka-operator-0.45-kafka-agent
  • ... 8 more
See record for full details 12 Jan
  • No fix available
MINI-wxr5-w52p-3fhq
  • MinimOS/keycloak-fips
  • MinimOS/keycloak-fips-advanced-compat
  • MinimOS/keycloak-fips-doc
See record for full details 18 Nov 2025
  • Fix available
MINI-7jg8-v5h2-rw44
  • MinimOS/kafka-strimzi-compat
  • MinimOS/kafka_exporter-strimzi-compat
  • MinimOS/prometheus-jmx-exporter-strimzi-compat
  • MinimOS/strimzi-kafka-operator
  • MinimOS/strimzi-kafka-operator-cluster-operator
  • ... 8 more
See record for full details 12 Nov 2025
  • Fix available
MINI-xgq9-3wgg-p433
  • MinimOS/keycloak
  • MinimOS/keycloak-advanced-compat
  • MinimOS/keycloak-doc
See record for full details 04 Nov 2025
  • Fix available
GHSA-45p5-v273-3qqr
  • Maven/io.vertx:vertx-web
Vert.x-Web vulnerable to Stored Cross-site Scripting in directory listings via file names 22 Oct 2025
  • Fix available
  • Severity - 2.3 (Low)
CVE-2025-11966
  • github.com/vert-x3/vertx-web
See record for full details 22 Oct 2025
  • Fix available
  • Severity - 6.4 (Medium)