RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

May 2026Clear ×Project: KeycloakClear ×
Keycloak26.6.2SecurityMay 19, 2026

A maintenance release with numerous disclosed security fixes, dependency updates, enhancements, and bug fixes. It also corrects forced object deletion during the operator upgrade path.

Action needed (6)

  • securityhighCVE-2026-33871: HTTP/2 CONTINUATION frame flood denial of service

    The release fixes the HTTP/2 CONTINUATION frame flood denial-of-service issue identified by CVE-2026-33871.

  • securityhighCVE-2026-33870: HTTP request smuggling through chunked extension parsing

    The release corrects the HTTP request smuggling primitive caused by chunked extension quoted-string parsing, identified by CVE-2026-33870.

  • securityhighBouncycastle updates for CVE-2026-0636, CVE-2026-3505, and CVE-2026-5598

    The release updates bouncycastle for CVE-2026-0636, CVE-2026-3505, and CVE-2026-5598.

  • securityhighCVE-2026-7504: Redirect URI validation bypass

    The release corrects the redirect URI validation bypass in Keycloak, identified by CVE-2026-7504.

  • securitymediumCVE-2026-5588: Bouncy Castle bcpkix cryptographic algorithm vulnerability

    The release updates the bcpkix modules affected by the broken or risky cryptographic algorithm vulnerability in the Bouncy Castle Crypto Package for Java, identified by CVE-2026-5588.

  • securityPermission and policy call ordering in admin/api

    The release corrects the ordering of permission and policy calls in admin/api that led to exposure of a client ID.

Check if affected (12)

  • securityhighCVE-2026-7307: Denial of service at the /saml endpoint

    Applies if you use /saml.

    The release fixes the denial-of-service issue caused by a crafted request to the /saml endpoint, identified by CVE-2026-7307.

  • securityhighCVE-2026-7571: Access token disclosure and implicit flow bypass

    Applies if you use implicit flow.

    The release fixes access token disclosure and implicit flow bypass through forged client data, identified by CVE-2026-7571.

  • securityhighCVE-2026-7507: Session fixation in the OIDC login flow

    Applies if you use OIDC login flow.

    The release fixes session fixation in the OIDC login flow that could lead to account takeover, identified by CVE-2026-7507.

  • + 9 more on the release page
Source
Browse by month