RATATOSKRATATOSK
Sign in

Keycloak

26.5.2Security
Jan 23, 2026

ACTION 3OTHER 14

Keycloak 26.5.2 is a maintenance release with security fixes alongside ordinary bug fixes and enhancements. The security updates affect third-party dependencies and Keycloak's token issuance logic.

Action needed (3)

  • securitymediumCVE-2025-67735 in netty-codec-http

    CVE-2025-67735 addresses request smuggling via CRLF injection in netty-codec-http. The fix ships in Keycloak 26.5.2.

  • securitymediumCVE-2025-66560 in io.quarkus/quarkus-rest

    CVE-2025-66560 addresses the Quarkus REST worker thread exhaustion vulnerability in io.quarkus/quarkus-rest. The fix ships in Keycloak 26.5.2.

  • securitymediumCVE-2025-14559 in keycloak-services

    CVE-2025-14559 addresses a business logic flaw in keycloak-services that allowed unauthorized token issuance for disabled users. The fix ships in Keycloak 26.5.2.

All 14 other recorded changesfixes 12 · additions 1 · value changes 1

fixes (12)

  • Can not get through SSO login if using a custom attribute with default value
  • Deadlock in Infinispan virtual threads
  • IDToken contains duplicate address claims
  • User admin events don't show role, group mapping, reset password like events
  • Database Migration fails when updating to 26.5.0 on MS SQL
  • cache-remote-host becomes mandatory at build time when using clusterless feature
  • Unmanaged Attributes Type (Only administrators can view) allows admin API to set Unmanaged Attributes
  • Regression (26.5.1): Organizations domain resolution fails on MariaDB/MySQL due to ORG/ORG_DOMAIN collation mismatch
  • Keycloak should not allow matrix parameters in URLs as we don't use them
  • Keycloak supported specs should list DPoP as supported
  • OIDCIdentityProviderConfig issuer configuration
  • Possible mismatch of charset/collation between columns on mysql/mariadb

additions (1)

  • Keycloak should warn when ISPN or JGROUPS is running in debug level logging

value changes (1)

  • Ignore OpenAPI artifacts when disabled
Add Keycloak to your stack

A weekly email arrives when a release needs action. Like the security patches in this release.

Add to stack