StackRadar

keycloak 0.3.0 Helm chart

sb-helm-charts

Scored 14 Sept 2026

A Helm chart for Keycloak - Open Source Identity and Access Management

Version 0.3.0 10 months agoapp version 26.0.6 0Artifact Hub

keycloak 0.3.0 deploys 2 container images: library/postgres and quay.io/keycloak/keycloak. Across them, 253 findings1 critical, 1 high 1 on CISA KEV. The highest contribution is RHSA-2025:11992 in sqlite 3.34.1-7.el9_3, fixed in 0:3.34.1-8.el9_6.

Radar Score

2,5901125226

253 findings over 2 of 2 images measured

KEV confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
library/postgres16-alpine00456493
quay.io/keycloak/keycloak26.0.611211702,097

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

253 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-hf67-5vvq-fm3rkeycloak-services@26.0.626.6.2
LowGHSA-c4c3-7fpv-j4q5netty-handler@4.1.111.Final4.1.137.Final
LowRHSA-2026:28253libtasn1@4.16.0-8.el9_10:4.16.0-10.el9_8
LowGHSA-x4p7-7chp-64hqkeycloak-server-spi-private@26.0.626.5.5
LowGHSA-x4p7-7chp-64hqkeycloak-services@26.0.626.5.5
LowALPINE-CVE-2026-54874openssl@3.5.7-r03.5.8-r0
LowGHSA-h4wv-g838-66g3keycloak-services@26.0.626.5.7
LowGHSA-5pvg-856g-cp85netty-resolver-dns@4.1.111.Final4.1.135.Final
LowALPINE-CVE-2026-63075openssl@3.5.7-r03.5.8-r0
LowGHSA-3p8m-j85q-pgmjnetty-codec@4.1.111.Final4.1.125.Final
LowGHSA-mj4r-2hfc-f8p6netty-codec@4.1.111.Final4.1.133.Final
LowGHSA-c653-97m9-rcg9netty-handler@4.1.111.Final4.1.135.Final
LowRHSA-2025:8655glibc@2.34-125.el9_5.10:2.34-168.el9_6.19
LowGHSA-93wv-jw9v-4972netty-codec-http2@4.1.111.Final4.1.136.Final
LowGHSA-6jqx-86gh-f27wnetty-codec-http@4.1.111.Final4.1.136.Final
LowGHSA-f2hx-5fx3-hmcvkeycloak-services@26.0.626.5.7
LowGHSA-mvh2-crg5-v77cnetty-codec-http@4.1.111.Final4.1.136.Final
LowGHSA-m297-3jv9-m927keycloak-services@26.0.626.5.5
LowGHSA-558v-64gr-wgg4netty-codec@4.1.111.Final4.1.136.Final
LowGHSA-c3fc-8qff-9hwxbcprov-jdk18on@1.78.11.84
LowRHSA-2026:18599p11-kit@0.25.3-2.el90:0.26.2-1.el9
LowGHSA-hj93-h7pg-fh6vkeycloak-services@26.0.626.5.7
LowGHSA-cjm2-j6cm-6p6mkeycloak-services@26.0.626.5.7
LowRHSA-2025:7077libtasn1@4.16.0-8.el9_10:4.16.0-9.el9
LowALPINE-CVE-2026-75803openssl@3.5.7-r03.5.8-r0
LowGHSA-676x-f7gg-47vcnetty-resolver-dns@4.1.111.Final4.1.135.Final
LowGHSA-wg6q-6289-32hpbcpkix-jdk18on@1.78.11.84
LowGHSA-g9gq-3pfx-2gw2owasp-java-html-sanitizer@20240325.120260101.1
LowRHSA-2026:42895java-21-openjdk@1:21.0.5.0.11-2.el91:21.0.12.0.8-1.2.el9
LowGHSA-794g-x443-36f7keycloak-services@26.0.6no fix listed
LowGHSA-w4p5-rfh6-cwrvkeycloak-services@26.0.626.6.2
LowGHSA-32h4-44jj-c5vxkeycloak-services@26.0.626.6.4
LowGO-2026-4341stdlib@go1.24.61.24.12
LowRHSA-2025:18824java-21-openjdk@1:21.0.5.0.11-2.el91:21.0.9.0.10-1.el9
LowGHSA-j92g-9f8w-j867postgresql@42.7.442.7.12
LowGHSA-7xf9-4jfc-wgm4keycloak-services@26.0.626.5.6
LowGHSA-cphf-4846-3xx9vertx-core@4.5.104.5.24
LowGHSA-wv3h-x6c4-r867keycloak-services@26.0.626.4.9
LowGHSA-hq3p-w4xv-x7vpkeycloak-services@26.0.626.6.2
LowGHSA-xxqh-mfjm-7mv9netty-codec-http@4.1.111.Final4.1.133.Final
LowGHSA-h5fg-jpgr-rv9cvertx-web@4.5.104.5.22
LowGHSA-fccg-mwvh-qqg4netty-handler@4.1.111.Final4.1.137.Final
LowGHSA-4cx2-fc23-5wg6bcpkix-jdk18on@1.78.11.79
LowRHSA-2025:0426java-21-openjdk@1:21.0.5.0.11-2.el91:21.0.6.0.7-1.el9
LowGHSA-q4f6-jm68-57wwnetty-codec-http@4.1.111.Final4.1.136.Final
LowALPINE-CVE-2026-76642util-linux@2.42.1-r02.42.3-r0
LowRHSA-2026:20597glibc@2.34-125.el9_5.10:2.34-270.el9_8
LowGHSA-6cqp-g7gg-8hr5netty-codec-http@4.1.111.Final4.1.136.Final
LowGHSA-72hv-8253-57qqjackson-core@2.17.22.18.6
LowRHSA-2026:42952glibc@2.34-125.el9_5.10:2.34-274.el9_8

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.3.0latest10 months ago26.0.611252262,590

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/sb-helm-charts/keycloak.svg)](https://charts.stackradar.io/charts/sb-helm-charts/keycloak)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.