[Git][security-tracker-team/security-tracker][master] Add CVE-2026-90997/keycloak, itp'ed

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 18 14:02:12 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dc252cc6 by Salvatore Bonaccorso at 2026-09-18T15:01:39+02:00
Add CVE-2026-90997/keycloak, itp'ed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -630,7 +630,7 @@ CVE-2026-92230 (Apache Karaf's XmlUtils cached XML parser/transformer factories
 CVE-2026-91039 (Authentication Bypass by Spoofing vulnerability in team-alembic ash_au ...)
 	NOT-FOR-US: team-alembic ash_authentication
 CVE-2026-90997 (A flaw was found in Keycloak. When deployed in stateless mode with MyS ...)
-	TODO: check
+	- keycloak <itp> (bug #1088287)
 CVE-2026-90986 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Tim ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-90887 (Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <=  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc252cc61162fdd9e9786c8b16687ed274dcfabb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc252cc61162fdd9e9786c8b16687ed274dcfabb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/ec2862e7/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list