A maintenance release with numerous disclosed security fixes, dependency updates, enhancements, and bug fixes. It also corrects forced object deletion during the operator upgrade path.
Action needed (6)
securityhighCVE-2026-33871: HTTP/2 CONTINUATION frame flood denial of service
The release fixes the
HTTP/2CONTINUATIONframe flood denial-of-service issue identified by CVE-2026-33871.securityhighCVE-2026-33870: HTTP request smuggling through chunked extension parsing
The release corrects the HTTP request smuggling primitive caused by chunked extension quoted-string parsing, identified by CVE-2026-33870.
securityhighBouncycastle updates for CVE-2026-0636, CVE-2026-3505, and CVE-2026-5598
The release updates bouncycastle for CVE-2026-0636, CVE-2026-3505, and CVE-2026-5598.
securityhighCVE-2026-7504: Redirect URI validation bypass
The release corrects the redirect URI validation bypass in Keycloak, identified by CVE-2026-7504.
securitymediumCVE-2026-5588: Bouncy Castle
bcpkixcryptographic algorithm vulnerabilityThe release updates the
bcpkixmodules affected by the broken or risky cryptographic algorithm vulnerability in the Bouncy Castle Crypto Package for Java, identified by CVE-2026-5588.securityPermission and policy call ordering in
admin/apiThe release corrects the ordering of permission and policy calls in
admin/apithat led to exposure of a client ID.
Check if affected (12)
securityhighCVE-2026-7307: Denial of service at the
/samlendpointApplies if you use
/saml.securityhighCVE-2026-7571: Access token disclosure and implicit flow bypass
Applies if you use
implicit flow.securityhighCVE-2026-7507: Session fixation in the OIDC login flow
Applies if you use
OIDC login flow.- + 9 more on the release page