Skip to content

Bump org.keycloak:keycloak-server-spi-private from 25.0.2 to 26.5.6 in /bulkfetchuserscustomendpoint - #1

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/bulkfetchuserscustomendpoint/org.keycloak-keycloak-server-spi-private-26.5.6
Closed

Bump org.keycloak:keycloak-server-spi-private from 25.0.2 to 26.5.6 in /bulkfetchuserscustomendpoint#1
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/bulkfetchuserscustomendpoint/org.keycloak-keycloak-server-spi-private-26.5.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 4, 2026

Copy link
Copy Markdown

Bumps org.keycloak:keycloak-server-spi-private from 25.0.2 to 26.5.6.

Release notes

Sourced from org.keycloak:keycloak-server-spi-private's releases.

26.5.6

26.5.5

... (truncated)

Commits
  • 7f8be2d Set version to 26.5.6
  • cb0e884 Stricter access control for listing realm and client roles (#47236)
  • fc3cb3c Check resource server when managing their resources
  • e54a993 Make sure time sync are respected and component config updated within a separ...
  • f1baf25 Stricter access control for managing permission tickets
  • 15106e1 Brief user representation should not return attributes
  • daf1a51 Ensure get organizations by member id requires managing realm
  • 55f59b1 Enforce org membership on member organizations endpoint
  • c498e84 Change links from issues.redhat.com to redhat.atlassian.net (#47181)
  • 5ac12be Em-Hyphens in SPI options on cache configuration page
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [org.keycloak:keycloak-server-spi-private](https://github.com/keycloak/keycloak) from 25.0.2 to 26.5.6.
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@25.0.2...26.5.6)

---
updated-dependencies:
- dependency-name: org.keycloak:keycloak-server-spi-private
  dependency-version: 26.5.6
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jun 4, 2026
@mikroozgurmaden

Copy link
Copy Markdown

Logo
Checkmarx One – Scan Summary & Details261e293f-4994-4cf2-af54-16b05c9867a9


New Issues (11) Checkmarx found the following issues in this Pull Request
# Severity Issue Source File / Package Checkmarx Insight
1 CRITICAL CVE-2026-42581 Maven-io.netty:netty-codec-http-4.1.130.Final
detailsRecommended version: 4.1.133.Final
Description: Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.133.Final and 4.2.x prior to 4.2.13.Final, `HttpObje...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
2 CRITICAL CVE-2026-42584 Maven-io.netty:netty-codec-http-4.1.130.Final
detailsRecommended version: 4.1.133.Final
Description: Netty is an asynchronous, event-driven network application framework. Prior to 4.1.133.Final and 4.2.x prior to 4.2.13.Final and 5.0.0.Alpha1 and 5...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
3 HIGH CVE-2026-33870 Maven-io.netty:netty-codec-http-4.1.130.Final
detailsRecommended version: 4.1.133.Final
Description: Netty is an asynchronous, event-driven network application framework. In 'netty-microbench' versions through 4.1.131.Final and 4.2.x through 4.2.10...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
4 HIGH CVE-2026-33871 Maven-io.netty:netty-codec-http2-4.1.130.Final
detailsRecommended version: 4.1.133.Final
Description: A remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
5 HIGH CVE-2026-42583 Maven-io.netty:netty-codec-4.1.130.Final
detailsRecommended version: 4.1.133.Final
Description: Netty is an asynchronous, event-driven network application framework. Prior to 4.1.133.Final and io.netty:netty-codec-compression versions prior t...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
6 HIGH CVE-2026-42585 Maven-io.netty:netty-codec-http-4.1.130.Final
detailsRecommended version: 4.1.133.Final
Description: Netty is an asynchronous, event-driven network application framework. Prior to 4.1.133.Final, 4.2.x prior to 4.2.13.Final and 5.0.0.Alpha1 and 5.0....
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
7 HIGH CVE-2026-42587 Maven-io.netty:netty-codec-http2-4.1.130.Final
detailsRecommended version: 4.1.133.Final
Description: `HttpContentDecompressor` accepts a `maxAllocation` parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
8 HIGH CVE-2026-42587 Maven-io.netty:netty-codec-http-4.1.130.Final
detailsRecommended version: 4.1.133.Final
Description: `HttpContentDecompressor` accepts a `maxAllocation` parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
9 HIGH CVE-2026-9087 Maven-org.keycloak:keycloak-services-26.5.6
detailsRecommended version: 26.6.2.redhat-00003
Description: A flaw was found in Keycloak versions 26.3.0 and after. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not b...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
10 MEDIUM CVE-2026-1002 Maven-io.vertx:vertx-core-4.5.23
detailsRecommended version: 4.5.24
Description: The Vert.x Web static handler component cache can be manipulated to deny the access to static files served by the handler using specifically crafte...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
11 LOW CVE-2026-42578 Maven-io.netty:netty-handler-proxy-4.1.130.Final
detailsRecommended version: 4.1.133.Final
Description: Netty is an asynchronous, event-driven network application framework. Prior to 4.1.133.Final and 4.2.x prior to 4.2.13.Final, Netty's "HttpProxyHan...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package

Fixed Issues (49) Great job! The following issues were fixed in this Pull Request
Severity Issue Source File / Package
HIGH CVE-2024-10039 Maven-org.keycloak:keycloak-core-25.0.2
HIGH CVE-2024-10270 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2025-3501 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2025-66021 Maven-com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer-20240325.1
HIGH CVE-2025-7365 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-1486 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-1529 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-2092 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-2603 Maven-org.keycloak:keycloak-server-spi-private-25.0.2
HIGH CVE-2026-2603 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-3009 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-3047 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-3121 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2022-1438 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2024-11734 Maven-org.keycloak:keycloak-server-spi-private-25.0.2
MEDIUM CVE-2024-11734 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2024-11736 Maven-org.keycloak:keycloak-core-25.0.2
MEDIUM CVE-2024-11736 Maven-org.keycloak:keycloak-common-25.0.2
MEDIUM CVE-2024-11736 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2024-4629 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2024-8883 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2024-9666 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2024-9666 Maven-org.keycloak:keycloak-common-25.0.2
MEDIUM CVE-2024-9666 Maven-org.keycloak:keycloak-core-25.0.2
MEDIUM CVE-2025-11429 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-12110 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-12390 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-1391 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-14559 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-14777 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-14778 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-2559 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-3910 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-7962 Maven-org.eclipse.angus:angus-mail-2.0.1
MEDIUM CVE-2025-8419 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2026-0707 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2026-0871 Maven-org.keycloak:keycloak-server-spi-private-25.0.2
LOW CVE-2024-10492 Maven-org.keycloak:keycloak-services-25.0.2
LOW CVE-2024-4028 Maven-org.keycloak:keycloak-core-25.0.2
LOW CVE-2025-12150 Maven-org.keycloak:keycloak-services-25.0.2
LOW CVE-2025-13881 Maven-org.keycloak:keycloak-services-25.0.2
LOW CVE-2025-14082 Maven-org.keycloak:keycloak-server-spi-private-25.0.2
LOW CVE-2025-14083 Maven-org.keycloak:keycloak-services-25.0.2
LOW CVE-2025-5416 Maven-org.keycloak:keycloak-services-25.0.2
LOW CVE-2025-5416 Maven-org.keycloak:keycloak-core-25.0.2
LOW CVE-2026-1035 Maven-org.keycloak:keycloak-services-25.0.2
LOW CVE-2026-1190 Maven-org.keycloak:keycloak-services-25.0.2
LOW CVE-2026-2733 Maven-org.keycloak:keycloak-services-25.0.2
LOW Cxeb68d52e-5509 Maven-commons-codec:commons-codec-1.11

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

@dependabot @github

dependabot Bot commented on behalf of github Jul 2, 2026

Copy link
Copy Markdown
Author

Superseded by #4.

@dependabot dependabot Bot closed this Jul 2, 2026
@dependabot
dependabot Bot deleted the dependabot/maven/bulkfetchuserscustomendpoint/org.keycloak-keycloak-server-spi-private-26.5.6 branch July 2, 2026 03:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant