A maintenance release with numerous disclosed security fixes, dependency updates, enhancements, and bug fixes. It also corrects forced object deletion during the operator upgrade path.
Action needed (6)
securityhighCVE-2026-33871: HTTP/2 CONTINUATION frame flood denial of service
The release fixes the
HTTP/2CONTINUATIONframe flood denial-of-service issue identified by CVE-2026-33871.securityhighCVE-2026-33870: HTTP request smuggling through chunked extension parsing
The release corrects the HTTP request smuggling primitive caused by chunked extension quoted-string parsing, identified by CVE-2026-33870.
securityhighBouncycastle updates for CVE-2026-0636, CVE-2026-3505, and CVE-2026-5598
The release updates bouncycastle for CVE-2026-0636, CVE-2026-3505, and CVE-2026-5598.
securityhighCVE-2026-7504: Redirect URI validation bypass
The release corrects the redirect URI validation bypass in Keycloak, identified by CVE-2026-7504.
securitymediumCVE-2026-5588: Bouncy Castle
bcpkixcryptographic algorithm vulnerabilityThe release updates the
bcpkixmodules affected by the broken or risky cryptographic algorithm vulnerability in the Bouncy Castle Crypto Package for Java, identified by CVE-2026-5588.securityPermission and policy call ordering in
admin/apiThe release corrects the ordering of permission and policy calls in
admin/apithat led to exposure of a client ID.
Check if affected (12)
securityhighCVE-2026-7307: Denial of service at the
/samlendpointApplies if you use
/saml.The release fixes the denial-of-service issue caused by a crafted request to the
/samlendpoint, identified by CVE-2026-7307.securityhighCVE-2026-7571: Access token disclosure and implicit flow bypass
Applies if you use
implicit flow.The release fixes access token disclosure and implicit flow bypass through forged client data, identified by CVE-2026-7571.
securityhighCVE-2026-7507: Session fixation in the OIDC login flow
Applies if you use
OIDC login flow.The release fixes session fixation in the OIDC login flow that could lead to account takeover, identified by CVE-2026-7507.
- + 9 more on the release page