← All tasks
javakeycloak/keycloak #51785Repaired task

Multiple CVEs inherited from Apache DS used for testing

envgap__keycloak__keycloak-51785

01 / FAILURE SIGNATURE

Captured in a clean container

[ERROR] The archive file /root/.m2/repository/com/github/eirslett/node/24.9.0/node-24.9.0-linux-x64.tar.gz is corrupted and will be deleted. Please try the build again.

02 / ENVIRONMENT RECIPE

Base commit
e0530edea61d21647b0a4b808cfa0e21955fb81f
Manifest
pom.xml
Reproduce
mvn -B -q -Dgpg.skip -Dmaven.javadoc.skip=true -Dcheckstyle.skip -DskipTests package
Run under trace
mvn -B -q -Dgpg.skip -Dmaven.javadoc.skip=true -Dcheckstyle.skip -DskipTests package
Reference environment fix used for admission
diff --git a/pom.xml b/pom.xml
index 0082093e7c..19e19cc6e4 100644
--- a/pom.xml
+++ b/pom.xml
@@ -126,7 +126,7 @@
         <!-- Others -->
         <apacheds.version>2.0.0.AM27</apacheds.version>
         <apacheds.codec.version>2.1.8</apacheds.codec.version>
-        <kerby.version>2.1.0</kerby.version>
+        <kerby.version>2.1.2</kerby.version>
         <google.zxing.version>3.4.0</google.zxing.version>
         <freemarker.version>2.3.32</freemarker.version>
         <sundrio.version>0.200.0</sundrio.version>
@@ -715,6 +715,12 @@
                 <type>pom</type>
                 <scope>import</scope>
             </dependency>
+            <!-- Override mina-core version from api-parent BOM to fix CVE-2026-47065 -->
+            <dependency>
+                <groupId>org.apache.mina</groupId>
+                <artifactId>mina-core</artifactId>
+                <version>2.2.9</version>
+            </dependency>
             <dependency>
                 <groupId>org.apache.jmeter</groupId>
                 <artifactId>ApacheJMeter_java</artifactId>
diff --git a/testsuite/integration-arquillian/tests/base/pom.xml b/testsuite/integration-arquillian/tests/base/pom.xml
index ba2cc86011..b0b71d3cd5 100644
--- a/testsuite/integration-arquillian/tests/base/pom.xml
+++ b/testsuite/integration-arquillian/tests/base/pom.xml
@@ -61,12 +61,6 @@
         <dependency>
             <groupId>org.keycloak</groupId>
             <artifactId>keycloak-util-embedded-ldap</artifactId>
-            <exclusions>
-                <exclusion>
-                    <groupId>org.bouncycastle</groupId>
-                    <artifactId>bcprov-jdk15on</artifactId>
-                </exclusion>
-            </exclusions>
         </dependency>
         <dependency>
             <groupId>org.keycloak</groupId>
diff --git a/testsuite/utils/pom.xml b/testsuite/utils/pom.xml
index f4ee8343bb..2f6ba90b3f 100755
--- a/testsuite/utils/pom.xml
+++ b/testsuite/utils/pom.xml
@@ -242,6 +242,12 @@
             <groupId>org.apache.kerby</groupId>
             <artifactId>ldap-backend</artifactId>
             <version>${kerby.version}</version>
+            <exclusions>
+                <exclusion>
+                    <groupId>org.bouncycastle</groupId>
+                    <artifactId>*</artifactId>
+                </exclusion>
+            </exclusions>
         </dependency>
 
         <dependency>
diff --git a/util/embedded-ldap/pom.xml b/util/embedded-ldap/pom.xml
index 9a1f239835..3c3a4bdc0b 100644
--- a/util/embedded-ldap/pom.xml
+++ b/util/embedded-ldap/pom.xml
@@ -88,6 +88,12 @@
             <groupId>org.apache.kerby</groupId>
             <artifactId>ldap-backend</artifactId>
             <version>${kerby.version}</version>
+            <exclusions>
+                <exclusion>
+                    <groupId>org.bouncycastle</groupId>
+                    <artifactId>*</artifactId>
+                </exclusion>
+            </exclusions>
         </dependency>
         <dependency>
             <groupId>org.apache.directory.server</groupId>

03 / ORIGINAL ISSUE TEXT

keycloak/keycloak #51785 · read the original issue
### Before reporting an issue

- [x] I have read and understood the above terms for submitting issues, and I understand that my issue may be closed without action if I do not follow them.

### Area

dependencies

### Describe the bug

org.keycloak:keycloak-util-embedded-ldap has dependencies on org.apache.kerby:ldap-backend, that brings a number of older dependencies, with two that have known CVEs.

org.bouncycastle:bcprov-jdk15on:1.70 (CVE-2023-33201, CVE-2024-29857, CVE-2024-30171, CVE-2024-34447, CVE-2025-8916, CVE-2026-5588)

org.apache.mina:mina-core:2.2.7 (CVE-2026-47065)

The above is the list from main, there are other CVEs for other release branches. See report on https://github.com/keycloak/keycloak/actions/workflows/scan-dependencies.yml for the latest run.

### Version

main

### Regression

- [ ] The issue is a regression

### Expected behavior

No CVEs in transitive dependencies

### Actual behavior

Multiple CVEs in transitive dependencies

### How to Reproduce?

See latest dependency scans:
https://github.com/keycloak/keycloak/actions/runs/32098560527

### Anything else?

Short term we should update the dependencies, but medium term we need to stop using Apache DS as it is no longer in active development/support with the last release several years ago.
Continue on GitHub ↗

04 / LABELS

Labels checked by running the task · needs human review

misspecificationsecurity
Label rules and the text that matched
[
  {
    "category": "misspecification",
    "rule": "diff.changes_existing_manifest_line",
    "source": "manifest_diff:pom.xml",
    "excerpt": "-        <kerby.version>2.1.0</kerby.version>\n+        <kerby.version>2.1.2</kerby.version>\n+            <!-- Override mina-core version from api-parent BOM to fix CVE-2026-47065 -->\n+            <dependency>\n+                <groupId>org.apache.mina</groupId>\n+                <artifactId>mina-core</artifactId>\n+                <version>2.2.9</version>\n+            </dependency>"
  },
  {
    "category": "security",
    "rule": "issue.security_keyword",
    "source": "issue_body",
    "excerpt": "with two that have known CVEs.\n\norg.bouncycastle:bcprov-jdk15on:1.70 (CVE-2023-33201, CVE-2024-29857, CVE-2024-30171, CVE-2024-34447, CVE-2025-8916, CVE-2026-5588)\n\norg.apache.mi"
  }
]

Mined from a merged pull request linked to the issue whose changed files are all environment files.

The base commit is the pull request's base, not the dated default-branch commit; the registry is pinned to the merge date so the pull request's own pins resolve.

Default commands from envgap default-recipe synthesizer v1; gold_files are the pull request's environment diff.

Preparation uses current registries. Historical package availability is not enforced here; execution metadata records this limitation separately from the oracle's date-bounding policy.