Keycloak
26.5.2Security2026年1月23日
Version 26.5.2では、セキュリティ修正に加えて、通常の不具合修正と機能改善も行われています。セキュリティ修正に関して、運用者に求められる追加設定変更は明示されておらず、アップグレードが対応内容です。
要対応 (3)
securitymedium
netty-codec-httpのリクエストスマグリング脆弱性の修正netty-codec-httpにおける CVE-2025-67735 の、CRLFインジェクションを利用したリクエストスマグリングの脆弱性が修正されています。securitymediumQuarkus RESTワーカースレッド枯渇の脆弱性の修正
io.における CVE-2025-66560 の、Quarkus RESTワーカースレッド枯渇の脆弱性が修正されています。quarkus/quarkus-rest securitymedium無効化ユーザーへの不正なトークン発行の修正
keycloak-servicesにおける CVE-2025-14559 の、無効化されたユーザーに不正なトークン発行を許してしまうビジネスロジックの欠陥が修正されています。
その他の記録済み変更 14 件すべてfixes 12 · additions 1 · value changes 1
fixes (12)
- Can not get through SSO login if using a custom attribute with default value
- Deadlock in Infinispan virtual threads
- IDToken contains duplicate address claims
- User admin events don't show role, group mapping, reset password like events
- Database Migration fails when updating to 26.5.0 on MS SQL
- cache-remote-host becomes mandatory at build time when using clusterless feature
- Unmanaged Attributes Type (Only administrators can view) allows admin API to set Unmanaged Attributes
- Regression (26.5.1): Organizations domain resolution fails on MariaDB/MySQL due to ORG/ORG_DOMAIN collation mismatch
- Keycloak should not allow matrix parameters in URLs as we don't use them
- Keycloak supported specs should list DPoP as supported
- OIDCIdentityProviderConfig issuer configuration
- Possible mismatch of charset/collation between columns on mysql/mariadb
additions (1)
- Keycloak should warn when ISPN or JGROUPS is running in debug level logging
value changes (1)
- Ignore OpenAPI artifacts when disabled
Keycloakをスタックに追加
対応が必要なリリースが出たときに、週次メールでお知らせします。 今回のセキュリティパッチも、その一例です。