Multiple CVEs inherited from Apache DS used for testing
envgap__keycloak__keycloak-51785
01 / FAILURE SIGNATURE
Captured in a clean container
[ERROR] The archive file /root/.m2/repository/com/github/eirslett/node/24.9.0/node-24.9.0-linux-x64.tar.gz is corrupted and will be deleted. Please try the build again.
02 / ENVIRONMENT RECIPE
- Base commit
e0530edea61d21647b0a4b808cfa0e21955fb81f- Manifest
pom.xml- Reproduce
mvn -B -q -Dgpg.skip -Dmaven.javadoc.skip=true -Dcheckstyle.skip -DskipTests package- Run under trace
mvn -B -q -Dgpg.skip -Dmaven.javadoc.skip=true -Dcheckstyle.skip -DskipTests package
Reference environment fix used for admission
diff --git a/pom.xml b/pom.xml
index 0082093e7c..19e19cc6e4 100644
--- a/pom.xml
+++ b/pom.xml
@@ -126,7 +126,7 @@
<!-- Others -->
<apacheds.version>2.0.0.AM27</apacheds.version>
<apacheds.codec.version>2.1.8</apacheds.codec.version>
- <kerby.version>2.1.0</kerby.version>
+ <kerby.version>2.1.2</kerby.version>
<google.zxing.version>3.4.0</google.zxing.version>
<freemarker.version>2.3.32</freemarker.version>
<sundrio.version>0.200.0</sundrio.version>
@@ -715,6 +715,12 @@
<type>pom</type>
<scope>import</scope>
</dependency>
+ <!-- Override mina-core version from api-parent BOM to fix CVE-2026-47065 -->
+ <dependency>
+ <groupId>org.apache.mina</groupId>
+ <artifactId>mina-core</artifactId>
+ <version>2.2.9</version>
+ </dependency>
<dependency>
<groupId>org.apache.jmeter</groupId>
<artifactId>ApacheJMeter_java</artifactId>
diff --git a/testsuite/integration-arquillian/tests/base/pom.xml b/testsuite/integration-arquillian/tests/base/pom.xml
index ba2cc86011..b0b71d3cd5 100644
--- a/testsuite/integration-arquillian/tests/base/pom.xml
+++ b/testsuite/integration-arquillian/tests/base/pom.xml
@@ -61,12 +61,6 @@
<dependency>
<groupId>org.keycloak</groupId>
<artifactId>keycloak-util-embedded-ldap</artifactId>
- <exclusions>
- <exclusion>
- <groupId>org.bouncycastle</groupId>
- <artifactId>bcprov-jdk15on</artifactId>
- </exclusion>
- </exclusions>
</dependency>
<dependency>
<groupId>org.keycloak</groupId>
diff --git a/testsuite/utils/pom.xml b/testsuite/utils/pom.xml
index f4ee8343bb..2f6ba90b3f 100755
--- a/testsuite/utils/pom.xml
+++ b/testsuite/utils/pom.xml
@@ -242,6 +242,12 @@
<groupId>org.apache.kerby</groupId>
<artifactId>ldap-backend</artifactId>
<version>${kerby.version}</version>
+ <exclusions>
+ <exclusion>
+ <groupId>org.bouncycastle</groupId>
+ <artifactId>*</artifactId>
+ </exclusion>
+ </exclusions>
</dependency>
<dependency>
diff --git a/util/embedded-ldap/pom.xml b/util/embedded-ldap/pom.xml
index 9a1f239835..3c3a4bdc0b 100644
--- a/util/embedded-ldap/pom.xml
+++ b/util/embedded-ldap/pom.xml
@@ -88,6 +88,12 @@
<groupId>org.apache.kerby</groupId>
<artifactId>ldap-backend</artifactId>
<version>${kerby.version}</version>
+ <exclusions>
+ <exclusion>
+ <groupId>org.bouncycastle</groupId>
+ <artifactId>*</artifactId>
+ </exclusion>
+ </exclusions>
</dependency>
<dependency>
<groupId>org.apache.directory.server</groupId>03 / ORIGINAL ISSUE TEXT
keycloak/keycloak #51785 · read the original issue
### Before reporting an issue - [x] I have read and understood the above terms for submitting issues, and I understand that my issue may be closed without action if I do not follow them. ### Area dependencies ### Describe the bug org.keycloak:keycloak-util-embedded-ldap has dependencies on org.apache.kerby:ldap-backend, that brings a number of older dependencies, with two that have known CVEs. org.bouncycastle:bcprov-jdk15on:1.70 (CVE-2023-33201, CVE-2024-29857, CVE-2024-30171, CVE-2024-34447, CVE-2025-8916, CVE-2026-5588) org.apache.mina:mina-core:2.2.7 (CVE-2026-47065) The above is the list from main, there are other CVEs for other release branches. See report on https://github.com/keycloak/keycloak/actions/workflows/scan-dependencies.yml for the latest run. ### Version main ### Regression - [ ] The issue is a regression ### Expected behavior No CVEs in transitive dependencies ### Actual behavior Multiple CVEs in transitive dependencies ### How to Reproduce? See latest dependency scans: https://github.com/keycloak/keycloak/actions/runs/32098560527 ### Anything else? Short term we should update the dependencies, but medium term we need to stop using Apache DS as it is no longer in active development/support with the last release several years ago.
04 / LABELS
Labels checked by running the task · needs human review
misspecificationsecurityLabel rules and the text that matched
[
{
"category": "misspecification",
"rule": "diff.changes_existing_manifest_line",
"source": "manifest_diff:pom.xml",
"excerpt": "- <kerby.version>2.1.0</kerby.version>\n+ <kerby.version>2.1.2</kerby.version>\n+ <!-- Override mina-core version from api-parent BOM to fix CVE-2026-47065 -->\n+ <dependency>\n+ <groupId>org.apache.mina</groupId>\n+ <artifactId>mina-core</artifactId>\n+ <version>2.2.9</version>\n+ </dependency>"
},
{
"category": "security",
"rule": "issue.security_keyword",
"source": "issue_body",
"excerpt": "with two that have known CVEs.\n\norg.bouncycastle:bcprov-jdk15on:1.70 (CVE-2023-33201, CVE-2024-29857, CVE-2024-30171, CVE-2024-34447, CVE-2025-8916, CVE-2026-5588)\n\norg.apache.mi"
}
]Mined from a merged pull request linked to the issue whose changed files are all environment files.
The base commit is the pull request's base, not the dated default-branch commit; the registry is pinned to the merge date so the pull request's own pins resolve.
Default commands from envgap default-recipe synthesizer v1; gold_files are the pull request's environment diff.
Preparation uses current registries. Historical package availability is not enforced here; execution metadata records this limitation separately from the oracle's date-bounding policy.