K

Keycloak

K
Keycloak Security

nightly

Send the response headers HttpServerUtil is given sendResponseHeaders transmits the header block, so the headers the caller passed were being added to the response after it had already gone out and never reached the client. The only current caller does not assert on them, which is why this went unnoticed. Also: Fix that responses without a body don't have a transfer encoding. Closes #52362 Signed-…

K
Keycloak Security v26.8.0

26.8.0

Highlights This release features new capabilities for users and administrators of Keycloak. The highlights of this release are: Issue and verify digital wallet credentials with OID4VCI and OID4VP Automate user provisioning across identity systems with the SCIM API Run multi-cluster deployments without an external cache using stateless mode (now supported) Simpler administration with automatic inde…

K
Keycloak Security v26.7.5

26.7.5

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #50996 [CVE-2026-16103] Incomplete fix for CVE-2026-9798 (Keycloak CIBA brute-force lockout bypass at token redemption) oidc #51278 [CVE-2026-18206] Client policy source-host wildcard domains match non-subdomain suffixes oidc #51280 [CVE-2026-18203] Group policy child-extensio…

K
Keycloak Security v26.7.4

26.7.4

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #52834 [CVE-2026-90997] Default MySQL/MariaDB row counts make stateless replay gates accept reused artifacts #52835 [CVE-2026-79651] Keycloak Unauthenticated Denial of Service via Unbounded Locale Caching #52836 [CVE-2026-74909] Incomplete fix: percent-encoded semicolon bypass…

K
Keycloak Security v26.7.3

26.7.3

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #50785 CVE-2026-35563: LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname ldap #50997 [CVE-2026-16093] Required signed-JWT assertion policy can be bypassed with unsigned assertion headers oidc #50998 [CVE-20…

K
Keycloak Security v26.7.2

26.7.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #49570 CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation dependencies #50616 [CVE-2026-14613] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass via Role Groups Endpoint admin/fine-grained-permissions #50955 [CVE-2026-59888 and…

K
Keycloak Security v26.7.1

26.7.1

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #49429 [CVE-2026-9793] JWE request object bypasses requestObjectSignatureAlg enforcement oidc #50445 [CVE-2026-4629] Privilege escalation via hardcoded role mapper injection in manage-clients admin/api #50569 [CVE-2026-14209] Keycloak Admin UI Extension `brute-force-user` User…

K
Keycloak Security v26.7.0

26.7.0

Highlights This release features new capabilities for users and administrators of Keycloak. The highlights of this release are: Automate user provisioning with the SCIM API (preview) Simplified multi-cluster high availability without external caches (preview) Enhanced reverse proxy guides with blueprints for HAProxy and Traefik Step-up authentication for SAML clients Read on to learn more about ea…

K
Keycloak Security v26.6.4

26.6.4

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #50344 CVE-2026-9099 Keycloak: group-admin escalation to realm-admin #50345 CVE-2026-9083 Keycloak: keycloak: information disclosure through arbitrary filesystem path probing #50347 CVE-2026-9086 Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validatio…

K
Keycloak Security v26.6.3

26.6.3

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #47707 CVE-2026-4800 lodash vulnerable to Code Injection via `_.template` imports key names account/ui #47935 [CVE-2026-4874] Server-Side Request Forgery via OIDC token endpoint manipulation oidc #48036 [CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverifie…

K
Keycloak Security v26.6.2

26.6.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #47485 CVE-2026-33871 HTTP/2 CONTINUATION Frame Flood Denial of Service #47486 CVE-2026-33870 RFC violation: HTTP Request Smuggling primitive via Chunked Extension Quoted-String Parsing #47932 [CVE-2026-4628] Improper Access Control on Keycloak Server through UMA resource mana…

K
Keycloak Security v26.6.1

26.6.1

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #47276 CVE-2026-4366 Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling core #47619 CVE-2026-4633 Keycloak user enumeration via identity-first login core Enhancements #47839 Update CloudNativePG to 1.29 #47909 Database data at rest encryption Bugs #47435 Auror…

K
Keycloak Security v26.6.0

26.6.0

Highlights This release features new capabilities for users and administrators of Keycloak. The highlights of this release are: JWT Authorization Grant, enabling external-to-internal token exchange using externally signed JWT assertions. Federated client authentication, eliminating the need to manage individual client secrets in Keycloak. Workflows, enabling administrators to automate realm admini…

K
Keycloak Security v26.5.7

26.5.7

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #45493 CVE-2025-14083 keycloak-server: Keycloak: Improper Access Control in Admin REST API leads to information disclosure admin/api #45569 CVE-2026-1002 - io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files #47069 CVE-2026…