UNCLASSIFIED - NO CUI

Skip to content

chore(findings): opensource/keycloak/keycloak-fips

Summary

opensource/keycloak/keycloak-fips has 4 new findings discovered during continuous monitoring.

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=opensource/keycloak/keycloak-fips&tag=26.4.2-fips&branch=master

EPSS (Exploit Prediction Scoring System) provides an estimate of the likelihood that a vulnerability will be exploited in the wild.

KEV (Known Exploited Vulnerabilities) indicates whether a vulnerability is actively being exploited according to CISA.

id source severity package impact workaround epss_score kev
CVE-2025-12390 Twistlock CVE Medium org.keycloak_keycloak-services-26.4.2 N/A false
CVE-2025-10939 Twistlock CVE Low org.keycloak_keycloak-quarkus-server-26.4.2 N/A false
GHSA-rg35-5v25-mqvp Anchore CVE Medium keycloak-services-26.4.2 N/A N/A
GHSA-c6cm-5gc7-c3f4 Anchore CVE Low keycloak-quarkus-server-26.4.2 N/A N/A

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=opensource/keycloak/keycloak-fips&tag=26.4.2-fips&branch=master

Novel Tidelift Findings (Experimental)

opensource/keycloak/keycloak-fips has 5 novel Tidelift findings discovered during continuous monitoring.

NOTE: This table is for Iron Bank evaluation and testing purposes. No action required by vendors.

id cvss score package impact workaround epss_score kev
CVE-2025-8916 6.3 org.bouncycastle:bc-fips-2.0.0 0.00063 false
CVE-2025-8916 6.3 org.bouncycastle:bcpkix-fips-2.0.7 0.00063 false
CVE-2025-8885 6.3 org.bouncycastle:bc-fips-2.0.0 0.00063 false
CVE-2025-11966 io.vertx:vertx-web-4.5.21 Directory listing is a common use case of the library Deactivate directory listing N/A false
CVE-2025-11965 io.vertx:vertx-web-4.5.21 StaticHandler and files listing is a common use case for the library N/A false

Tasks

Contributor:

  • Apply the StatusReview label to this issue for a merge request review and wait for feedback

OR

  • Provide justifications for findings in the VAT (docs)
  • Apply the StatusVerification label to this issue for a VAT justifications review and wait for feedback

Iron Bank:

  • Review findings and justifications

Note: If the above process is rejected for any reason, the Review or Verification label will be removed and the issue will be sent back to To-Do. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Review or Verification label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information