K

Keycloak

K
Keycloak Security

nightly

[OID4VCI] Make key attestations configurable in Admin Console (#51261) Closes #51179 Signed-off-by: forkimenjeckayang <forkimenjeckayang@gmail.com>

K
Keycloak Security v26.7.0

26.7.0

Highlights This release features new capabilities for users and administrators of Keycloak. The highlights of this release are: Automate user provisioning with the SCIM API (preview) Simplified multi-cluster high availability without external caches (preview) Enhanced reverse proxy guides with blueprints for HAProxy and Traefik Step-up authentication for SAML clients Read on to learn more about ea…

K
Keycloak Security v26.6.4

26.6.4

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #50344 CVE-2026-9099 Keycloak: group-admin escalation to realm-admin #50345 CVE-2026-9083 Keycloak: keycloak: information disclosure through arbitrary filesystem path probing #50347 CVE-2026-9086 Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validatio…

K
Keycloak Security v26.6.3

26.6.3

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #47707 CVE-2026-4800 lodash vulnerable to Code Injection via `_.template` imports key names account/ui #47935 [CVE-2026-4874] Server-Side Request Forgery via OIDC token endpoint manipulation oidc #48036 [CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverifie…

K
Keycloak Security v26.6.2

26.6.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #47485 CVE-2026-33871 HTTP/2 CONTINUATION Frame Flood Denial of Service #47486 CVE-2026-33870 RFC violation: HTTP Request Smuggling primitive via Chunked Extension Quoted-String Parsing #47932 [CVE-2026-4628] Improper Access Control on Keycloak Server through UMA resource mana…

K
Keycloak Security v26.6.1

26.6.1

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #47276 CVE-2026-4366 Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling core #47619 CVE-2026-4633 Keycloak user enumeration via identity-first login core Enhancements #47839 Update CloudNativePG to 1.29 #47909 Database data at rest encryption Bugs #47435 Auror…

K
Keycloak Security v26.6.0

26.6.0

Highlights This release features new capabilities for users and administrators of Keycloak. The highlights of this release are: JWT Authorization Grant, enabling external-to-internal token exchange using externally signed JWT assertions. Federated client authentication, eliminating the need to manage individual client secrets in Keycloak. Workflows, enabling administrators to automate realm admini…

K
Keycloak Security v26.5.7

26.5.7

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #45493 CVE-2025-14083 keycloak-server: Keycloak: Improper Access Control in Admin REST API leads to information disclosure admin/api #45569 CVE-2026-1002 - io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files #47069 CVE-2026…