Skip to content

correct fixed-version metadata and add reporter credit for GHSA-wmxr-6j5f-838p#7280

Open
1seal wants to merge 1 commit intogithub:1seal/advisory-improvement-7280from
1seal:codex/keycloak-ghsa-credit
Open

correct fixed-version metadata and add reporter credit for GHSA-wmxr-6j5f-838p#7280
1seal wants to merge 1 commit intogithub:1seal/advisory-improvement-7280from
1seal:codex/keycloak-ghsa-credit

Conversation

@1seal
Copy link
Copy Markdown

@1seal 1seal commented Apr 1, 2026

title:

body:

this PR proposes metadata corrections for GHSA-wmxr-6j5f-838p / CVE-2026-2092.

the current advisory data still marks 26.5.5 as affected for the three Maven packages below and does not include a structured credits[] section.

public sources supporting the metadata update:

  • Keycloak issue #46912 (CVE-2026-2092 saml broker encrypted assertion injection) was closed on 2026-03-05 and labeled release/26.2.14, release/26.4.10, release/26.5.5, and release/26.6.0
  • Keycloak release 26.5.5 was published on 2026-03-05
  • the advisory already references fix commit b40a25908d937bb0563ea516487bc2c7c1d92508

requested changes:

  • align affected[].ranges[].events[] and affected[].versions[] so publicly fixed releases are not still listed as affected
  • if curator policy allows it, add structured credits[] for the original reporter/finder

packages currently showing the incorrect fixed-release state:

  • org.keycloak:keycloak-saml-adapter-core
  • org.keycloak:keycloak-saml-core
  • org.keycloak:keycloak-services

source links:

credit request:

  • reporter/finder: Oleh Konko
  • GitHub handle: @1seal
  • contact: keycloak.response.team@gmail.com

note:

  • this PR is not attempting to relitigate the vulnerability itself. the CVE already exists and the fix commit is already referenced. this only corrects the public advisory record and requests structured attribution.

@github-actions github-actions bot changed the base branch from main to 1seal/advisory-improvement-7280 April 1, 2026 15:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant