[Git][security-tracker-team/security-tracker][master] Add CVE-2026-90997/keycloak, itp'ed
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 18 14:02:12 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
dc252cc6 by Salvatore Bonaccorso at 2026-09-18T15:01:39+02:00
Add CVE-2026-90997/keycloak, itp'ed
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -630,7 +630,7 @@ CVE-2026-92230 (Apache Karaf's XmlUtils cached XML parser/transformer factories
CVE-2026-91039 (Authentication Bypass by Spoofing vulnerability in team-alembic ash_au ...)
NOT-FOR-US: team-alembic ash_authentication
CVE-2026-90997 (A flaw was found in Keycloak. When deployed in stateless mode with MyS ...)
- TODO: check
+ - keycloak <itp> (bug #1088287)
CVE-2026-90986 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Tim ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-90887 (Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc252cc61162fdd9e9786c8b16687ed274dcfabb
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc252cc61162fdd9e9786c8b16687ed274dcfabb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/ec2862e7/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list