RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Feb 2026Clear ×Project: KeycloakClear ×
Keycloak26.5.4SecurityFeb 20, 2026

A maintenance release with five disclosed security fixes, one new capability, and ten corrected bugs. It contains no operator prerequisites or dependency-manifest entries.

Action needed (2)

  • securitymediumCVE-2026-0707, authorization header parsing

    This release corrects authorization header parsing that could bypass security controls.

  • securitylowCVE-2025-5416, keycloak-core environment information disclosure

    This release fixes environment information disclosure in keycloak-core.

Check if affected (4)

  • securitymediumCVE-2026-2575, excessive SAMLRequest decompression

    Applies if you use SAML.

    This release fixes excessive SAMLRequest decompression that can cause denial of service.

  • securitylowCVE-2026-1190, SAML brokering response delay

    Applies if you use SAML brokering.

    This release fixes the unchecked NotOnOrAfter handling in SubjectConfirmationData that can delay SAML brokering responses.

  • securitylowCVE-2026-2733, disabled client check for Docker Registry Protocol

    Applies if you use the Docker Registry Protocol.

    This release adds the missing check for disabled clients in the Docker Registry Protocol.

  • + 1 more on the release page
Source
Browse by month