RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Apr 2026Clear ×Project: KeycloakClear ×
Keycloak26.6.1SecurityApr 15, 2026

Keycloak 26.6.1 is a maintenance release with two described security fixes in the core. It also contains dependency updates, an enhancement, and bug fixes.

Action needed (2)

  • securitymediumCVE-2026-4366, blind server-side request forgery via HTTP redirect handling

    Keycloak 26.6.1 fixes blind server-side request forgery through HTTP redirect handling in core.

  • securitylowCVE-2026-4633, user enumeration via identity-first login

    Keycloak 26.6.1 fixes user enumeration through identity-first login in core.

Source
Keycloak26.6.0SecurityApr 8, 2026

A substantial operator-facing feature and maintenance release adds new capabilities, configuration and deployment options, performance improvements, and many bug fixes. It also changes selected defaults, deprecates Token Exchange v1, and includes security and correctness fixes for authorization, identity and URL handling, SCIM, anti-phishing checks, and UMA token validation.

Action needed (6)

  • securitySeparate password and OTP brute force protection

    Password and OTP brute force protection are now separate by default to prevent OTP bypass attacks.

  • securityResourceAdminManager URL construction validation

    URL construction in ResourceAdminManager is validated against matrix parameter injection.

  • securityClient retrieval anti-ID phishing check

    Client retrieval now includes the missing anti-ID phishing check.

  • breakingZero-downtime patch releases enabled by default

    Zero-downtime patch releases are now promoted to supported and enabled by default.

  • breaking--truststore-kubernetes-enabled enabled by default

    The behavior controlled by --truststore-kubernetes-enabled is enabled by default.

  • breakingTen-second default not-before validation

    The default not-before validation period is now 10 seconds instead of 0.

Check if affected (7)

  • securityWorkflows admin permission boundaries

    Applies if you use Workflows.

    Workflows execution no longer bypasses admin permission boundaries from manage-realm to realm-admin.

  • securityOrganizations login IdP alias disclosure

    Applies if you use Organizations.

    Organizations login no longer leaks IdP aliases when no Organization is resolved, preventing IdP and tenant enumeration.

  • securitySCIM PUT body ID override protection

    Applies if you use SCIM.

    The SCIM PUT endpoint no longer permits resource modification through a body ID override.

  • + 4 more on the release page

Plan ahead (1)

  • deprecatedToken Exchange v1 deprecation

    Applies if you use Token Exchange v1.

    Token Exchange v1 is deprecated in this release.

Source
Keycloak26.5.7SecurityApr 2, 2026

A security maintenance release fixes seven disclosed vulnerabilities. It also upgrades Quarkus and corrects an error caused by requests without a Host header.

Action needed (1)

  • securitymediumCVE-2026-1002 static handler component cache

    CVE-2026-1002 fixes a flaw in the io.vertx/vertx-core static handler component cache that could deny access to static files.

Check if affected (6)

  • securityhighCVE-2026-4634 scope processing

    Applies if you use Scope Processing.

    CVE-2026-4634 fixes an application-level denial-of-service issue in scope processing.

  • securityhighCVE-2026-4636 UMA policy resource injection

    Applies if you use UMA.

    CVE-2026-4636 fixes a UMA policy resource injection issue that could grant unauthorized permissions across users.

  • securityhighCVE-2026-3872 OIDC redirect URI validation

    Applies if you use OIDC.

    CVE-2026-3872 fixes a redirect URI validation bypass caused by ..;/ path traversal in the OIDC authentication endpoint.

  • + 3 more on the release page
Source
Browse by month