StackRadar

keycloak Helm chart

bhuwanupadhyayVerified publisher

Scored 21 Sept 2026

A Helm chart for Keycloak

Latest 1.0.0app version 20.0.2 0Artifact Hub

keycloak 1.0.0 deploys 2 container images: quay.io/keycloak/keycloak and bitnami/postgresql. Across the 1 measured, 443 findings5 critical, 13 high 4 on CISA KEV. The highest contribution is RHSA-2024:2722 in glibc 2.28-211.el8, fixed in 0:2.28-236.el8_9.13.

Radar Score

6,454513112313

443 findings over 1 of 2 images measured

KEV ×4 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
quay.io/keycloak/keycloak20.0.25131123136,454
bitnami/postgresql15.2.0-debian-11-r2unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

443 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-jp4c-xjxw-mgf9pip@9.0.326.1
LowGHSA-v897-pv23-r8cwkeycloak-quarkus-server@20.0.2no fix listed
LowGHSA-vjr8-56p3-fmqqkeycloak-quarkus-server@20.0.226.4.4
LowGHSA-fjf4-6f34-w64qkeycloak-services@20.0.2no fix listed
LowGHSA-8g9r-9wjw-37j4keycloak-services@20.0.2no fix listed
LowGHSA-gv3v-2cpp-3pmqkeycloak-quarkus-server@20.0.226.5.6
LowGHSA-5565-3c98-g6jcwildfly-elytron-http-oidc@1.18.3.Final2.2.9.Final
LowGHSA-5565-3c98-g6jcwildfly-elytron@1.18.3.Final2.2.9.Final
LowGHSA-4q93-v92x-p89fkeycloak-server-spi-private@20.0.2no fix listed
LowGHSA-4q93-v92x-p89fkeycloak-services@20.0.2no fix listed
LowGHSA-jgvc-jfgh-rjvvjose4j@0.7.90.9.3
LowGHSA-q4xq-445g-g6chkeycloak-core@20.0.2no fix listed
LowRHSA-2026:61248libxml2@2.9.7-15.el80:2.9.7-21.el8_10.7
LowGHSA-4pgc-gfrr-wcmgkeycloak-services@20.0.2no fix listed
LowGHSA-rhgq-f8x5-j2jckeycloak-services@20.0.226.4.12
LowGHSA-58qw-9mgm-455vpip@9.0.326.1
LowGHSA-5545-r4hg-rj4mkeycloak-quarkus-server@20.0.226.0.6
LowRHSA-2025:12980glibc@2.28-211.el80:2.28-251.el8_10.25
LowGHSA-5v8v-xvjv-57x7keycloak-services@20.0.226.4.13
LowGHSA-c25h-c27q-5qpvkeycloak-ldap-federation@20.0.222.0.12
LowRHBA-2026:47115coreutils@8.30-13.el80:8.30-20.el8_10
LowGHSA-7fpj-9hr8-28vhkeycloak-services@20.0.222.0.10
LowGHSA-63v5-26vq-m4vmkeycloak-services@20.0.2no fix listed
LowGHSA-gg57-587f-h5v6infinispan-core@13.0.10.Final14.0.25.Final
LowGHSA-gg57-587f-h5v6infinispan-cachestore-remote@13.0.10.Final14.0.25.Final
LowGHSA-gg57-587f-h5v6infinispan-client-hotrod@13.0.10.Final14.0.25.Final
LowGHSA-gg57-587f-h5v6infinispan-commons@13.0.10.Final14.0.25.Final
LowGHSA-wxmm-q36w-r9xjmariadb-java-client@3.0.83.3.5
LowGHSA-m2w5-7xhv-w6fhkeycloak-services@20.0.2no fix listed
LowGHSA-22rm-wp4x-v5cxkeycloak-services@20.0.226.4.13
LowGHSA-w573-9ffj-6ff9netty-transport-native-epoll@4.1.82.Final4.1.135.Final
LowGHSA-g78x-7vwx-9f58keycloak-services@20.0.226.4.9
LowGHSA-j75r-vf64-6rrhresteasy-reactive-common@2.13.3.Final3.0.0.Alpha4
LowGHSA-594w-2fwp-jwrckeycloak-services@20.0.2no fix listed
LowGHSA-6q37-7866-h27jkeycloak-services@20.0.226.5.0
LowGHSA-6g26-7cx5-mrrgkeycloak-services@20.0.226.7.0
LowGHSA-xh32-c9wx-phrpkeycloak-services@20.0.2no fix listed
LowGHSA-7g5x-9c4v-4w5rkeycloak-services@20.0.226.4.4
LowGHSA-fghv-69vj-qj49netty-codec-http@4.1.82.Final4.1.125.Final
LowGHSA-8hc5-rmgf-qx6pkeycloak-ldap-federation@20.0.223.0.1
LowGHSA-8hc5-rmgf-qx6pkeycloak-services@20.0.223.0.1
LowRHSA-2026:36734libxml2@2.9.7-15.el80:2.9.7-21.el8_10.6
LowGHSA-6vgw-5pg2-w6jppip@9.0.326.0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.0.0latest20.0.25131123136,454

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/bhuwanupadhyay/keycloak.svg)](https://charts.stackradar.io/charts/bhuwanupadhyay/keycloak)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 21 Sept 2026 · scanned 21 Sept 2026 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.