RATATOSKRATATOSK
ログイン

Keycloak

26.5.2Security
2026年1月23日

ACTION 3OTHER 14

Version 26.5.2では、セキュリティ修正に加えて、通常の不具合修正と機能改善も行われています。セキュリティ修正に関して、運用者に求められる追加設定変更は明示されておらず、アップグレードが対応内容です。

要対応 (3)

  • securitymediumnetty-codec-http のリクエストスマグリング脆弱性の修正

    netty-codec-http における CVE-2025-67735 の、CRLFインジェクションを利用したリクエストスマグリングの脆弱性が修正されています。

  • securitymediumQuarkus RESTワーカースレッド枯渇の脆弱性の修正

    io.quarkus/quarkus-rest における CVE-2025-66560 の、Quarkus RESTワーカースレッド枯渇の脆弱性が修正されています。

  • securitymedium無効化ユーザーへの不正なトークン発行の修正

    keycloak-services における CVE-2025-14559 の、無効化されたユーザーに不正なトークン発行を許してしまうビジネスロジックの欠陥が修正されています。

その他の記録済み変更 14 件すべてfixes 12 · additions 1 · value changes 1

fixes (12)

  • Can not get through SSO login if using a custom attribute with default value
  • Deadlock in Infinispan virtual threads
  • IDToken contains duplicate address claims
  • User admin events don't show role, group mapping, reset password like events
  • Database Migration fails when updating to 26.5.0 on MS SQL
  • cache-remote-host becomes mandatory at build time when using clusterless feature
  • Unmanaged Attributes Type (Only administrators can view) allows admin API to set Unmanaged Attributes
  • Regression (26.5.1): Organizations domain resolution fails on MariaDB/MySQL due to ORG/ORG_DOMAIN collation mismatch
  • Keycloak should not allow matrix parameters in URLs as we don't use them
  • Keycloak supported specs should list DPoP as supported
  • OIDCIdentityProviderConfig issuer configuration
  • Possible mismatch of charset/collation between columns on mysql/mariadb

additions (1)

  • Keycloak should warn when ISPN or JGROUPS is running in debug level logging

value changes (1)

  • Ignore OpenAPI artifacts when disabled
Keycloakをスタックに追加

対応が必要なリリースが出たときに、週次メールでお知らせします。 今回のセキュリティパッチも、その一例です。

スタックに追加