RATATOSKRATATOSK
ログイン

Keycloak

26.5.1Security
2026年1月14日

CHECK 1OTHER 13

Keycloak 26.5.1には、`Organization` 機能に関するセキュリティ修正が含まれています。不具合修正や性能改善、HTTP応答とレルム管理に関する拡張も含まれます。

影響確認 (1)

  • securityOrganization 機能でアカウント名が自動表示・入力される問題の修正

    Organization 機能を利用している場合に該当します。

    Organization 機能で、アカウント名がユーザー名/パスワードフォームに自動表示され、入力欄にも入る問題を修正しました。

その他の記録済み変更 13 件すべてfixes 10 · value changes 2 · additions 1

fixes (10)

  • 403 Forbidden when assigning realm-management client roles despite FGAP disabled (regression in 26.4.0+)
  • Create Realm button is missing when user has create-realm role
  • Admin UI: slow response time listing second user page
  • Bug in JWTClientAuthenticator and JWTClientSecretAuthenticator causes NPE
  • Enable visibility of Role Mapping tab for users with view-users role
  • Failed upgrade to 26.4.7 - sql generated for manual database upgrade contains invalid statements
  • Realm-level admininistrators can no longer use Admin Console since 26.3.0 (UI fails to render)
  • Failure when decrypting SAML Response since 26.5.0
  • Upgrade to 26.5.0 failing due to FK_ORG_INVITATION_ORG constraint
  • UI Bug: WebAuthn passkey list is broken in keycloak v2 theme

value changes (2)

  • x-robots HTTP header missing for static Keycloak resources, and REST endpoint responses
  • Performance improvement: Missing indexes on BROKER_LINK table columns

additions (1)

  • Allow full managing of realms from master realm without global admin role
Keycloakをスタックに追加

対応が必要なリリースが出たときに、週次メールでお知らせします。 今回のセキュリティパッチも、その一例です。

スタックに追加