A maintenance release with five disclosed security fixes, one new capability, and ten corrected bugs. It contains no operator prerequisites or dependency-manifest entries.
Action needed (2)
securitymediumCVE-2026-0707, authorization header parsing
This release corrects authorization header parsing that could bypass security controls.
securitylowCVE-2025-5416,
keycloak-coreenvironment information disclosureThis release fixes environment information disclosure in
keycloak-core.
Check if affected (4)
securitymediumCVE-2026-2575, excessive
SAMLRequestdecompressionApplies if you use SAML.
This release fixes excessive
SAMLRequestdecompression that can cause denial of service.securitylowCVE-2026-1190, SAML brokering response delay
Applies if you use SAML brokering.
This release fixes the unchecked
NotOnOrAfterhandling inSubjectConfirmationDatathat can delay SAML brokering responses.securitylowCVE-2026-2733, disabled client check for Docker Registry Protocol
Applies if you use the Docker Registry Protocol.
This release adds the missing check for disabled clients in the Docker Registry Protocol.
- + 1 more on the release page