[Git][security-tracker-team/security-tracker][master] Add new keycloak issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 20 07:04:28 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
710de0d4 by Salvatore Bonaccorso at 2026-07-20T08:03:17+02:00
Add new keycloak issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3037,21 +3037,21 @@ CVE-2026-21761 (HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (
 CVE-2026-21760 (HCL DevOps Loop is affected by an Unauthorized Access to Admin Functio ...)
 	NOT-FOR-US: HCL
 CVE-2026-16108 (A flaw was found in the default-groups REST endpoint and realm represe ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-16106 (A flaw was found in the admin REST API of Keycloak, a solution for ide ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-16104 (A flaw was found in the authentication configuration endpoint of the k ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-16103 (A flaw was found in the keycloak-services component of Keycloak. This  ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-16093 (Keycloak provides a mechanism called Client Policies to enforce securi ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-16089 (A flaw was found in the keycloak-services component of Red Hat Build o ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-16073 (A security vulnerability has been detected in AstrBotDevs AstrBot up t ...)
 	NOT-FOR-US: AstrBotDevs AstrBot
 CVE-2026-16072 (A flaw was found in the organization management component of Keycloak. ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-16017 (A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. I ...)
 	NOT-FOR-US: mosaxiv clawlet
 CVE-2026-16016 (A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This  ...)
@@ -3067,7 +3067,7 @@ CVE-2026-16009 (A vulnerability was detected in itsourcecode Hospital Management
 CVE-2026-16008 (A security vulnerability has been detected in sagold json-schema-libra ...)
 	NOT-FOR-US: sagold json-schema-library
 CVE-2026-15943 (A flaw was found in the Keycloak keycloak-services component, which ha ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-15783 (A missing authorization vulnerability was identified in GitHub Enterpr ...)
 	NOT-FOR-US: Github Enterprise Server
 CVE-2026-15380 (A non-administrator interactive user can obtain full SYSTEM code execu ...)
@@ -3595,7 +3595,7 @@ CVE-2026-15997 (Out-of-bounds write vulnerability in Legion of the Bouncy Castle
 CVE-2026-15982 (The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Auto ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15945 (A flaw was found in the group search functionality of the Keycloak ser ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-15759 (The ChatHelp \u2013 Click to Chat Button, WooCommerce Chat to Order &  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15737 (AWS Bedrock AgentCore Python SDK is an open-source Python library that ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/710de0d42be20c799b8c82e9f67fc370df37f5a0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/710de0d42be20c799b8c82e9f67fc370df37f5a0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260720/5b41bcb8/attachment.htm>


More information about the debian-security-tracker-commits mailing list