RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Aug 2026Clear ×Project: KeycloakClear ×
Keycloak26.7.2SecurityAug 19, 2026

A maintenance release with disclosed security fixes, a cleartext vault-keystore password correction, a Quarkus dependency upgrade, and other bug corrections. The fixes cover account and permission flows, secret handling, and runtime dependencies.

Action needed (2)

  • securitymediumCVE-2026-59888 and CVE-2026-59889 fixes in jackson-databind

    jackson-databind is upgraded to 2.21.5 to address CVE-2026-59888 and CVE-2026-59889. The dependency update ships in this Keycloak release.

  • securitymediumCVE-2026-45292 OpenTelemetry Java SDK memory allocation correction

    CVE-2026-45292 corrects unbounded memory allocation in W3C Baggage Propagation in the OpenTelemetry Java SDK.

Check if affected (6)

  • securitycriticalCVE-2026-18963 reset-credentials flow bypass correction

    Applies if you use the reset-credentials flow.

    CVE-2026-18963 corrects an unauthenticated account takeover caused by a bypass in the reset-credentials flow.

  • securityhighCVE-2026-15571 predictable account-linking hash correction

    Applies if you use oidc.

    CVE-2026-15571 corrects the predictable account-linking hash that enabled account takeover through a malicious oidc client.

  • securitymediumCVE-2026-14613 fine-grained admin permissions bypass correction

    Applies if you use the admin/fine-grained-permissions API.

    CVE-2026-14613 corrects a fine-grained admin permissions bypass through the admin/fine-grained-permissions Role Groups endpoint.

  • + 3 more on the release page
Source
Keycloak26.7.1SecurityAug 5, 2026

A maintenance release with security fixes and additional bug fixes. The security fixes require upgrading, and the ordinary bug fixes require no operator action beyond upgrading.

Check if affected (12)

  • securityhighCVE-2026-15573 unnormalized URI matching in pathmatcher

    Applies if you use pathmatcher.

    CVE-2026-15573 fixes an authorization bypass caused by unnormalized URI matching in pathmatcher.

  • securityhighCVE-2026-15572 DCR protocol mapper type-swap policy

    Applies if you use DCR.

    CVE-2026-15572 fixes a DCR protocol mapper type-swap policy bypass that allowed privilege escalation.

  • securityhighCVE-2026-16442 SAML broker login restriction

    Applies if you use the SAML broker.

    CVE-2026-16442 fixes a SAML identity-provider-initiated broker login bypass of the link-only restriction.

  • + 9 more on the release page
Source
Browse by month