RATATOSKRATATOSK
로그인

Keycloak

26.5.2Security
2026년 1월 23일

ACTION 3OTHER 14

이번 릴리스는 외부 의존성과 `keycloak-services`에 관한 보안 수정과 일반 버그 수정 및 개선을 포함합니다. 보안 수정 적용을 위한 업그레이드 외에 운영자 설정 변경이 명시되지는 않았습니다.

조치 필요 (3)

  • securitymediumnetty-codec-http의 CRLF 주입 요청 밀수 취약점 수정

    netty-codec-http에서 CRLF 주입으로 발생하는 요청 밀수 취약점을 수정했습니다. 관련 권고 식별자는 CVE-2025-67735입니다.

  • securitymediumio.quarkus/quarkus-rest 작업자 스레드 고갈 취약점 수정

    io.quarkus/quarkus-rest의 작업자 스레드 고갈 취약점을 수정했습니다. 관련 권고 식별자는 CVE-2025-66560입니다.

  • securitymedium비활성화된 사용자의 인증 토큰 발급 결함 수정

    비활성화된 사용자가 인증 토큰을 발급받을 수 있었던 keycloak-services의 비즈니스 로직 결함을 수정했습니다. 관련 권고 식별자는 CVE-2025-14559입니다.

그 외 기록된 변경 14건 전체fixes 12 · additions 1 · value changes 1

fixes (12)

  • Can not get through SSO login if using a custom attribute with default value
  • Deadlock in Infinispan virtual threads
  • IDToken contains duplicate address claims
  • User admin events don't show role, group mapping, reset password like events
  • Database Migration fails when updating to 26.5.0 on MS SQL
  • cache-remote-host becomes mandatory at build time when using clusterless feature
  • Unmanaged Attributes Type (Only administrators can view) allows admin API to set Unmanaged Attributes
  • Regression (26.5.1): Organizations domain resolution fails on MariaDB/MySQL due to ORG/ORG_DOMAIN collation mismatch
  • Keycloak should not allow matrix parameters in URLs as we don't use them
  • Keycloak supported specs should list DPoP as supported
  • OIDCIdentityProviderConfig issuer configuration
  • Possible mismatch of charset/collation between columns on mysql/mariadb

additions (1)

  • Keycloak should warn when ISPN or JGROUPS is running in debug level logging

value changes (1)

  • Ignore OpenAPI artifacts when disabled
Keycloak 스택에 추가

조치가 필요한 릴리스가 나왔을 때 주간 메일로 알려드립니다. 이번 릴리스의 보안 패치 같은 것들입니다.

스택에 추가