Skip to content

Bump org.keycloak:keycloak-services from 25.0.2 to 26.6.2 in /bulkfetchuserscustomendpoint - #2

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/bulkfetchuserscustomendpoint/org.keycloak-keycloak-services-26.6.2
Closed

Bump org.keycloak:keycloak-services from 25.0.2 to 26.6.2 in /bulkfetchuserscustomendpoint#2
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/bulkfetchuserscustomendpoint/org.keycloak-keycloak-services-26.6.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 4, 2026

Copy link
Copy Markdown

Bumps org.keycloak:keycloak-services from 25.0.2 to 26.6.2.

Release notes

Sourced from org.keycloak:keycloak-services's releases.

26.6.2

... (truncated)

Commits
  • 0a402f7 Set version to 26.6.2
  • 6ac4dc5 Override org.postgresql:postgresql version (#663)
  • fa6d83a Upgrade to Quarkus 3.33.1.1 (#627)
  • afb43d3 CVE-2026-37979 audience check for introspection endpoint (26.6) (#600)
  • 56d8e95 set only redirect_uri from client_data during restart (#620)
  • 2711d52 Wildcards should not be allowed if authority cannot be parsed (#607)
  • ce27972 Fix parsing SAML11 incorrect requests. (#609)
  • 8232aaa Windows Service fails on slower runners due to insufficient startup timeout (...
  • ef1d932 Better check for authSessionCookie in SessionCodeChecks (#603)
  • ba9a187 Enforce access check when resolving users during client scope evaluation (#539)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [org.keycloak:keycloak-services](https://github.com/keycloak/keycloak) from 25.0.2 to 26.6.2.
- [Release notes](https://github.com/keycloak/keycloak/releases)
- [Commits](keycloak/keycloak@25.0.2...26.6.2)

---
updated-dependencies:
- dependency-name: org.keycloak:keycloak-services
  dependency-version: 26.6.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jun 4, 2026
@mikroozgurmaden

Copy link
Copy Markdown

Logo
Checkmarx One – Scan Summary & Details9623dafa-ecfc-4845-b0e7-a29d23550318


New Issues (8) Checkmarx found the following issues in this Pull Request
# Severity Issue Source File / Package Checkmarx Insight
1 CRITICAL CVE-2026-42581 Maven-io.netty:netty-codec-http-4.1.132.Final
detailsRecommended version: 4.1.133.Final
Description: Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.133.Final and 4.2.x prior to 4.2.13.Final, `HttpObje...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
2 CRITICAL CVE-2026-42584 Maven-io.netty:netty-codec-http-4.1.132.Final
detailsRecommended version: 4.1.133.Final
Description: Netty is an asynchronous, event-driven network application framework. Prior to 4.1.133.Final and 4.2.x prior to 4.2.13.Final and 5.0.0.Alpha1 and 5...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
3 HIGH CVE-2026-42583 Maven-io.netty:netty-codec-4.1.132.Final
detailsRecommended version: 4.1.133.Final
Description: Netty is an asynchronous, event-driven network application framework. Prior to 4.1.133.Final and io.netty:netty-codec-compression versions prior t...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
4 HIGH CVE-2026-42585 Maven-io.netty:netty-codec-http-4.1.132.Final
detailsRecommended version: 4.1.133.Final
Description: Netty is an asynchronous, event-driven network application framework. Prior to 4.1.133.Final, 4.2.x prior to 4.2.13.Final and 5.0.0.Alpha1 and 5.0....
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
5 HIGH CVE-2026-42587 Maven-io.netty:netty-codec-http2-4.1.132.Final
detailsRecommended version: 4.1.133.Final
Description: `HttpContentDecompressor` accepts a `maxAllocation` parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
6 HIGH CVE-2026-42587 Maven-io.netty:netty-codec-http-4.1.132.Final
detailsRecommended version: 4.1.133.Final
Description: `HttpContentDecompressor` accepts a `maxAllocation` parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
7 HIGH CVE-2026-9087 Maven-org.keycloak:keycloak-services-26.6.2
detailsDescription: A flaw was found in Keycloak versions 26.3.0 and after. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not b...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
8 LOW CVE-2026-42578 Maven-io.netty:netty-handler-proxy-4.1.132.Final
detailsRecommended version: 4.1.133.Final
Description: Netty is an asynchronous, event-driven network application framework. Prior to 4.1.133.Final and 4.2.x prior to 4.2.13.Final, Netty's "HttpProxyHan...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package

Fixed Issues (57) Great job! The following issues were fixed in this Pull Request
Severity Issue Source File / Package
HIGH CVE-2024-10039 Maven-org.keycloak:keycloak-core-25.0.2
HIGH CVE-2024-10270 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2025-3501 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2025-66021 Maven-com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer-20240325.1
HIGH CVE-2025-7365 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-1486 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-1529 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-2092 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-2603 Maven-org.keycloak:keycloak-server-spi-private-25.0.2
HIGH CVE-2026-2603 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-3009 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-3047 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-3121 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-3872 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-4282 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-4634 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-4636 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-7504 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-7507 Maven-org.keycloak:keycloak-services-25.0.2
HIGH CVE-2026-7571 Maven-org.keycloak:keycloak-services-25.0.2
HIGH Cxfa47c4e4-5ef9 Maven-com.fasterxml.jackson.core:jackson-core-2.17.0
MEDIUM CVE-2022-1438 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2024-11734 Maven-org.keycloak:keycloak-server-spi-private-25.0.2
MEDIUM CVE-2024-11734 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2024-11736 Maven-org.keycloak:keycloak-core-25.0.2
MEDIUM CVE-2024-11736 Maven-org.keycloak:keycloak-common-25.0.2
MEDIUM CVE-2024-11736 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2024-4629 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2024-8883 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2024-9666 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2024-9666 Maven-org.keycloak:keycloak-common-25.0.2
MEDIUM CVE-2024-9666 Maven-org.keycloak:keycloak-core-25.0.2
MEDIUM CVE-2025-11429 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-12110 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-12390 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-1391 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-14559 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-14777 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-14778 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-2559 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-3910 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2025-7962 Maven-org.eclipse.angus:angus-mail-2.0.1
MEDIUM CVE-2025-8419 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2026-0707 Maven-org.keycloak:keycloak-services-25.0.2
MEDIUM CVE-2026-0871 Maven-org.keycloak:keycloak-server-spi-private-25.0.2
LOW CVE-2024-10492 Maven-org.keycloak:keycloak-services-25.0.2
LOW CVE-2024-4028 Maven-org.keycloak:keycloak-core-25.0.2
LOW CVE-2025-12150 Maven-org.keycloak:keycloak-services-25.0.2
LOW CVE-2025-13881 Maven-org.keycloak:keycloak-services-25.0.2
LOW CVE-2025-14082 Maven-org.keycloak:keycloak-server-spi-private-25.0.2
LOW CVE-2025-14083 Maven-org.keycloak:keycloak-services-25.0.2
LOW CVE-2025-5416 Maven-org.keycloak:keycloak-services-25.0.2
LOW CVE-2025-5416 Maven-org.keycloak:keycloak-core-25.0.2
LOW CVE-2026-1035 Maven-org.keycloak:keycloak-services-25.0.2
LOW CVE-2026-1190 Maven-org.keycloak:keycloak-services-25.0.2
LOW CVE-2026-2733 Maven-org.keycloak:keycloak-services-25.0.2
LOW Cxeb68d52e-5509 Maven-commons-codec:commons-codec-1.11

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

@dependabot @github

dependabot Bot commented on behalf of github Jun 4, 2026

Copy link
Copy Markdown
Author

Superseded by #3.

@dependabot dependabot Bot closed this Jun 4, 2026
@dependabot
dependabot Bot deleted the dependabot/maven/bulkfetchuserscustomendpoint/org.keycloak-keycloak-services-26.6.2 branch June 4, 2026 17:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant