# Keycloak 26.1.0 Vulerability issue

**URL:** https://forum.keycloak.org/t/keycloak-26-1-0-vulerability-issue/29530
**Category:** Getting advice
**Created:** [February 4, 2025, 6:36am UTC](https://forum.keycloak.org/t/keycloak-26-1-0-vulerability-issue/29530 "2025-02-04T06:36:12Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![ayyandurai.m](https://avatars.discourse-cdn.com/v4/letter/a/35a633/32.png) [@ayyandurai.m](https://forum.keycloak.org/u/ayyandurai.m)
#### Post date: [February 4, 2025, 6:36am UTC](https://forum.keycloak.org/t/keycloak-26-1-0-vulerability-issue/29530/1 "2025-02-04T06:36:12Z")

</div>

Hi,

We recently upgraded keycloak from 25.0.6 to 26.1.0 to resolve some security vulnerability issues.  
v26.1.0 also got following jar ‘io.quarkus.http.quarkus-http-core-5.3.3’ as HIGH vulnerable.

Is there any way to fix this issue, or can we expect some upgrade soon for this?

Really appreciate your response

Thank You,  
Ayyandurai M

---

<div class="post-metadata">

### Author: ![dasniko](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dasniko/32/2969_2.png) [@dasniko](https://forum.keycloak.org/u/dasniko)
#### Post date: [February 4, 2025, 7:14am UTC](https://forum.keycloak.org/t/keycloak-26-1-0-vulerability-issue/29530/2 "2025-02-04T07:14:15Z")

</div>

This is a community forum, Keycloak maintainers doesn’t read here.  
If you have questions to the project team, please visit the [GitHub repo](https://github.com/keycloak/keycloak), thanks.

---

<div class="post-metadata">

### Author: ![bpedersen2](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/bpedersen2/32/3934_2.png) [@bpedersen2](https://forum.keycloak.org/u/bpedersen2)
#### Post date: [February 5, 2025, 9:39am UTC](https://forum.keycloak.org/t/keycloak-26-1-0-vulerability-issue/29530/3 "2025-02-05T09:39:51Z")

</div>

Check [Keycloak.X, but secure – without vulnerable libraries](https://www.codecentric.de/wissens-hub/blog/keycloak-x-but-secure-without-vulnerable-libraries) for an idea on how build your own custom image with such deps patched if you need the patches urgently.

---

<div class="post-metadata">

### Author: ![dasniko](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dasniko/32/2969_2.png) [@dasniko](https://forum.keycloak.org/u/dasniko)
#### Post date: [February 5, 2025, 11:52am UTC](https://forum.keycloak.org/t/keycloak-26-1-0-vulerability-issue/29530/4 "2025-02-05T11:52:35Z")

</div>

Or just use 26.1.1, which was just relesed and the CVE is fixed.
