RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Mar 2026Clear ×Project: KeycloakClear ×
Keycloak26.5.6SecurityMar 19, 2026

A security and maintenance release that fixes disclosed vulnerabilities alongside ordinary bugs. The security fixes require upgrading, while the other fixes require no operator action beyond upgrading.

Check if affected (8)

  • securitymediumCVE-2026-1180, blind SSRF in OIDC Dynamic Client Registration

    Applies if you use OIDC Dynamic Client Registration.

    Keycloak 26.5.6 fixes the blind server-side request forgery vulnerability in OIDC Dynamic Client Registration via jwks_uri.

  • securitymediumCVE-2025-14777, Keycloak IDOR in realm client creation and deletion

    Applicability is not stated in the release notes.

    Keycloak 26.5.6 fixes the IDOR vulnerability in realm client creation and deletion.

  • securitymediumCVE-2026-3121, privilege escalation via manage-clients permission

    Applies if you configure manage-clients permission.

    Keycloak 26.5.6 fixes privilege escalation through the manage-clients permission.

  • + 5 more on the release page
Source
Keycloak26.5.5SecurityMar 5, 2026

This release fixes four disclosed security vulnerabilities involving SAML and identity brokering. The corrections address authentication, identity provider enforcement, broker login, and encrypted assertion handling.

Check if affected (4)

  • securityhighCVE-2026-3047 SAML broker authentication bypass

    Applies if you use SAML broker and configure a disabled SAML client.

    Keycloak 26.5.5 fixes an authentication bypass in the SAML broker caused by a disabled SAML client completing an IdP-initiated login.

  • securityhighCVE-2026-3009 disabled identity provider enforcement

    Applies if you configure Disabled Identity Provider.

    Keycloak 26.5.5 fixes improper enforcement of a disabled identity provider in IdentityBrokerService.

  • securityhighCVE-2026-2603 disabled SAML IdP broker login

    Applies if you configure Disabled SAML IdP.

    Keycloak 26.5.5 fixes an issue where a disabled SAML identity provider could still allow IdP-initiated broker login.

  • + 1 more on the release page
Source
Browse by month