A security-heavy maintenance release with vulnerability fixes, alongside correctness and performance corrections. It also updates the Quarkus dependency.
Action needed (4)
securityhighCVE-2026-79651 and unbounded locale caching
CVE-2026-79651 fixes an unauthenticated denial-of-service issue caused by unbounded locale caching. The fix ships in this release.
securityhighCVE-2026-74909 and matrix parameter stripping
CVE-2026-74909 completes the fix for a percent-encoded semicolon bypass of matrix parameter stripping in
PathMatcher. The fix ships in this release.securityhighCVE-2026-17526 and the
impersonationroleCVE-2026-17526 fixes privilege escalation involving the
impersonationrole impersonating a realm administrator. The fix ships in this release.securitymediumCVE-2026-19607 and username takeover
CVE-2026-19607 fixes a username takeover issue that could lead to account lockout. The fix ships in this release.
Check if affected (2)
securityhighCVE-2026-18212 and SAML Redirect DEFLATE helpers
Applies if you use SAML Redirect.
securityCVE-2026-90997 and stateless replay gate row counts
Applies if you use MySQL/MariaDB.