Keycloak
26.5.2SecurityKeycloak 26.5.2 is a maintenance release with security fixes alongside ordinary bug fixes and enhancements. The security updates affect third-party dependencies and Keycloak's token issuance logic.
Action needed (3)
securitymediumCVE-2025-67735 in
netty-codec-httpCVE-2025-67735 addresses request smuggling via CRLF injection in
netty-codec-http. The fix ships in Keycloak 26.5.2.securitymediumCVE-2025-66560 in
io.quarkus/quarkus-rest CVE-2025-66560 addresses the Quarkus REST worker thread exhaustion vulnerability in
io.. The fix ships in Keycloak 26.5.2.quarkus/quarkus-rest securitymediumCVE-2025-14559 in
keycloak-servicesCVE-2025-14559 addresses a business logic flaw in
keycloak-servicesthat allowed unauthorized token issuance for disabled users. The fix ships in Keycloak 26.5.2.
All 14 other recorded changesfixes 12 · additions 1 · value changes 1
fixes (12)
- Can not get through SSO login if using a custom attribute with default value
- Deadlock in Infinispan virtual threads
- IDToken contains duplicate address claims
- User admin events don't show role, group mapping, reset password like events
- Database Migration fails when updating to 26.5.0 on MS SQL
- cache-remote-host becomes mandatory at build time when using clusterless feature
- Unmanaged Attributes Type (Only administrators can view) allows admin API to set Unmanaged Attributes
- Regression (26.5.1): Organizations domain resolution fails on MariaDB/MySQL due to ORG/ORG_DOMAIN collation mismatch
- Keycloak should not allow matrix parameters in URLs as we don't use them
- Keycloak supported specs should list DPoP as supported
- OIDCIdentityProviderConfig issuer configuration
- Possible mismatch of charset/collation between columns on mysql/mariadb
additions (1)
- Keycloak should warn when ISPN or JGROUPS is running in debug level logging
value changes (1)
- Ignore OpenAPI artifacts when disabled
A weekly email arrives when a release needs action. Like the security patches in this release.