update to Keycloak version 26.5.5 #992
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|
CVE-2026-31988Path to dependency file: /Examples/OneTimePasswordJSExample/package.json Path to vulnerable library: /Examples/OneTimePasswordJSExample/node_modules/yauzl/package.json,/Examples/RadiusServiceAccountJSExample/node_modules/yauzl/package.json,/Examples/WebAuthnJSExample/node_modules/yauzl/package.json Dependency Hierarchy: -> keycloak-connect-26.1.1.tgz (Root Library) -> chromedriver-146.0.2.tgz -> extract-zip-2.0.1.tgz -> ❌ yauzl-2.10.0.tgz (Vulnerable Library) |
5.3 | Transitive yauzl-2.10.0.tgz |
keycloak-connect-26.1.1.tgz | Transitive 3.2.1 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2026-2739 | bn.js-4.12.3.tgz |
Base branch total remaining vulnerabilities: 4
Base branch commit: 98106905ceb59bead5da281e3f1b91caf341d7a2
Total libraries scanned: 186
Scan token: 593af84f99f3406c828c14f9577a422b