keycloak/rhbk-rhel9-operator vulnerabilities
CVEs whose affected-version data names the keycloak/rhbk-rhel9-operator package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-87743High· 7.5A flaw was found in Quarkus HTTP security
A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers. This allows the attacker to craft a URL that the secu…
▾ TwilightRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.43%via NVD
CVE-2026-17615High· 7.5A flaw was found in RESTEasy's SourceProvider
A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external …
▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.35%via NVD