Keycloak
26.5.1Security2026年1月14日
Keycloak 26.5.1には、`Organization` 機能に関するセキュリティ修正が含まれています。不具合修正や性能改善、HTTP応答とレルム管理に関する拡張も含まれます。
影響確認 (1)
security
Organization機能でアカウント名が自動表示・入力される問題の修正Organization機能を利用している場合に該当します。Organization機能で、アカウント名がユーザー名/パスワードフォームに自動表示され、入力欄にも入る問題を修正しました。
その他の記録済み変更 13 件すべてfixes 10 · value changes 2 · additions 1
fixes (10)
- 403 Forbidden when assigning realm-management client roles despite FGAP disabled (regression in 26.4.0+)
- Create Realm button is missing when user has create-realm role
- Admin UI: slow response time listing second user page
- Bug in JWTClientAuthenticator and JWTClientSecretAuthenticator causes NPE
- Enable visibility of Role Mapping tab for users with view-users role
- Failed upgrade to 26.4.7 - sql generated for manual database upgrade contains invalid statements
- Realm-level admininistrators can no longer use Admin Console since 26.3.0 (UI fails to render)
- Failure when decrypting SAML Response since 26.5.0
- Upgrade to 26.5.0 failing due to FK_ORG_INVITATION_ORG constraint
- UI Bug: WebAuthn passkey list is broken in keycloak v2 theme
value changes (2)
- x-robots HTTP header missing for static Keycloak resources, and REST endpoint responses
- Performance improvement: Missing indexes on BROKER_LINK table columns
additions (1)
- Allow full managing of realms from master realm without global admin role
Keycloakをスタックに追加
対応が必要なリリースが出たときに、週次メールでお知らせします。 今回のセキュリティパッチも、その一例です。