Keycloak
26.7.4SecurityA security-heavy maintenance release with vulnerability fixes, alongside correctness and performance corrections. It also updates the Quarkus dependency.
Action needed (4)
securityhighCVE-2026-79651 and unbounded locale caching
CVE-2026-79651 fixes an unauthenticated denial-of-service issue caused by unbounded locale caching. The fix ships in this release.
securityhighCVE-2026-74909 and matrix parameter stripping
CVE-2026-74909 completes the fix for a percent-encoded semicolon bypass of matrix parameter stripping in
PathMatcher. The fix ships in this release.securityhighCVE-2026-17526 and the
impersonationroleCVE-2026-17526 fixes privilege escalation involving the
impersonationrole impersonating a realm administrator. The fix ships in this release.securitymediumCVE-2026-19607 and username takeover
CVE-2026-19607 fixes a username takeover issue that could lead to account lockout. The fix ships in this release.
Check if affected (2)
securityhighCVE-2026-18212 and SAML Redirect DEFLATE helpers
Applies if you use SAML Redirect.
CVE-2026-18212 fixes native zlib state leaks in
SAML RedirectDEFLATE helpers. The fix ships in this release.securityCVE-2026-90997 and stateless replay gate row counts
Applies if you use MySQL/MariaDB.
CVE-2026-90997 fixes default
MySQL/MariaDBrow counts that let stateless replay gates accept reused artifacts. The fix ships in this release.
All 6 other recorded changesfixes 5 · value changes 1
fixes (5)
- <li><a href="https://github.com/keycloak/keycloak/issues/49635">#49635</a> Performance issue with 26.6.2 <code>dist/quarkus</code></li>
- <li><a href="https://github.com/keycloak/keycloak/issues/52172">#52172</a> Cached
RealmAdapter.returnsisUserManagedAccessAllowed() isEnabled()<code>infinispan</code></li> - <li><a href="https://github.com/keycloak/keycloak/issues/52173">#52173</a>
realm_clientis computed into a client's attributes and then persisted on save <code>admin/api</code></li> - <li><a href="https://github.com/keycloak/keycloak/issues/52233">#52233</a> Oracle 19 full client OCI driver crashes on startup since 26.6.0 — SQLFeatureNotSupportedException on setNetworkTimeout <code>dist/quarkus</code></li>
- <li><a href="https://github.com/keycloak/keycloak/issues/52241">#52241</a> Clicking on a sub group in the admin console throws an exception <code>admin/ui</code></li>
value changes (1)
- <li><a href="https://github.com/keycloak/keycloak/issues/52354">#52354</a> Upgrade to Quarkus 3.33.3.2 <code>dist/quarkus</code></li>
A weekly email arrives when a release needs action. Like the security patches in this release.