StackRadar

CVE-2026-18963

Critical

Advisory

Published 18 Aug 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.032
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
15
deployed by those charts
Fix available
3 of 3
affected packages

Flaw in the reset-credentials flow of the keycloak-services component

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
keycloak-servicesmaven26.0.6, 26.0.7, 26.0.8, 26.1.4+8 more26.4.15, 26.6.6, 26.7.213
keycloakbitnami20.0.5-6, 24.0.4-1, 26.3.3-0, 26.5.0-126.7.24
Keycloakbitnami24.0.4-126.7.21
OSV records
BIT-keycloak-2026-18963GHSA-4gv3-mc9p-5wqc

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
keycloakkubelauncherVerified publisher0.4.41 of 1See more

keycloak kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/keycloakdigest-pinnedafe3bd73d7cf
keycloak-services@26.7.1
26.7.2

Open the chart page →

1,251
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/keycloak:0.13.0b37408461b9b
keycloak-services@26.5.4
26.6.6

Open the chart page →

28,839
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
keycloak@20.0.5-6
26.7.2

Open the chart page →

37,373
arlas-aiasarlas-stackVerified publisher28.8.01 of 22See more

arlas-aias arlas-stack 28.8.0

1 of the 22 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
keycloak@26.3.3-0
keycloak-services@26.3.3
26.7.2
26.4.15

Open the chart page →

40,238
damap-chartdamapVerified publisher0.3.01 of 5See more

damap-chart damap 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.49409c59bdfb6
keycloak-services@26.4.7
26.4.15

Open the chart page →

13,936
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.6.39b0330756022
keycloak-services@26.6.3
26.6.6

Open the chart page →

4,586
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.1.4044a457e0498
keycloak-services@26.1.4
26.4.15

Open the chart page →

45,239
keycloakmt1905021.4.61 of 3See more

keycloak mt190502 1.4.6

1 of the 3 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.5.68d44614c7479
keycloak-services@26.5.6
26.6.6

Open the chart page →

2,901
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
keycloak@24.0.4-1
Keycloak@24.0.4-1
26.7.2
26.7.2

Open the chart page →

15,369
keycloakpascaliskeVerified publisher0.2.01 of 1See more

keycloak pascaliske 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.74388e2379b7e
keycloak-services@26.0.7
26.4.15

Open the chart page →

2,097
keycloaksb-helm-charts0.3.01 of 2See more

keycloak sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
keycloak-services@26.0.6
26.4.15

Open the chart page →

2,590
keycloakself-hosters-by-nightVerified publisher0.1.11 of 1See more

keycloak self-hosters-by-night 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.60aae0de7fca8
keycloak-services@26.6.4
26.6.6

Open the chart page →

518
keycloaksikalabs0.1.01 of 1See more

keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.3.36a7217a100bd
keycloak-services@26.3.3
26.4.15

Open the chart page →

1,690
wonder-mesh-netstrrl-helm2026.629.01 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

1 of the 3 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.009a381c715ab
keycloak-services@26.0.8
26.4.15

Open the chart page →

5,063
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:26.1.4044a457e0498
keycloak-services@26.1.4
26.4.15

Open the chart page →

45,239
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-18963.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
keycloak@26.5.0-1
keycloak-services@26.5.0
26.7.2
26.6.6

Open the chart page →

7,624

Container images carrying it

15 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/keycloak/keycloak:26.1.4044a457e0498
keycloak-services@26.1.4
26.4.15
2
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
keycloak@20.0.5-6
26.7.2
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
keycloak@24.0.4-1
Keycloak@24.0.4-1
26.7.2
26.7.2
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
keycloak@26.3.3-0
keycloak-services@26.3.3
26.7.2
26.4.15
1
ghcr.io/kubelauncher/keycloakafe3bd73d7cf
keycloak-services@26.7.1
26.7.2
1
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
keycloak@26.5.0-1
keycloak-services@26.5.0
26.7.2
26.6.6
1
ghcr.io/wundergraph/cosmo/keycloak:0.13.0b37408461b9b
keycloak-services@26.5.4
26.6.6
1
quay.io/keycloak/keycloak:26.009a381c715ab
keycloak-services@26.0.8
26.4.15
1
quay.io/keycloak/keycloak:26.60aae0de7fca8
keycloak-services@26.6.4
26.6.6
1
quay.io/keycloak/keycloak:26.0.74388e2379b7e
keycloak-services@26.0.7
26.4.15
1
quay.io/keycloak/keycloak:26.3.36a7217a100bd
keycloak-services@26.3.3
26.4.15
1
quay.io/keycloak/keycloak:26.5.68d44614c7479
keycloak-services@26.5.6
26.6.6
1
quay.io/keycloak/keycloak:26.49409c59bdfb6
keycloak-services@26.4.7
26.4.15
1
quay.io/keycloak/keycloak:26.6.39b0330756022
keycloak-services@26.6.3
26.6.6
1
quay.io/keycloak/keycloak:26.0.6a93d22e13b86
keycloak-services@26.0.6
26.4.15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.