Keycloak
26.5.2Security2026년 1월 23일
이번 릴리스는 외부 의존성과 `keycloak-services`에 관한 보안 수정과 일반 버그 수정 및 개선을 포함합니다. 보안 수정 적용을 위한 업그레이드 외에 운영자 설정 변경이 명시되지는 않았습니다.
조치 필요 (3)
securitymedium
netty-codec-http의 CRLF 주입 요청 밀수 취약점 수정netty-codec-http에서 CRLF 주입으로 발생하는 요청 밀수 취약점을 수정했습니다. 관련 권고 식별자는 CVE-2025-67735입니다.securitymedium
io.작업자 스레드 고갈 취약점 수정quarkus/quarkus-rest io.의 작업자 스레드 고갈 취약점을 수정했습니다. 관련 권고 식별자는 CVE-2025-66560입니다.quarkus/quarkus-rest securitymedium비활성화된 사용자의 인증 토큰 발급 결함 수정
비활성화된 사용자가 인증 토큰을 발급받을 수 있었던
keycloak-services의 비즈니스 로직 결함을 수정했습니다. 관련 권고 식별자는 CVE-2025-14559입니다.
그 외 기록된 변경 14건 전체fixes 12 · additions 1 · value changes 1
fixes (12)
- Can not get through SSO login if using a custom attribute with default value
- Deadlock in Infinispan virtual threads
- IDToken contains duplicate address claims
- User admin events don't show role, group mapping, reset password like events
- Database Migration fails when updating to 26.5.0 on MS SQL
- cache-remote-host becomes mandatory at build time when using clusterless feature
- Unmanaged Attributes Type (Only administrators can view) allows admin API to set Unmanaged Attributes
- Regression (26.5.1): Organizations domain resolution fails on MariaDB/MySQL due to ORG/ORG_DOMAIN collation mismatch
- Keycloak should not allow matrix parameters in URLs as we don't use them
- Keycloak supported specs should list DPoP as supported
- OIDCIdentityProviderConfig issuer configuration
- Possible mismatch of charset/collation between columns on mysql/mariadb
additions (1)
- Keycloak should warn when ISPN or JGROUPS is running in debug level logging
value changes (1)
- Ignore OpenAPI artifacts when disabled
Keycloak 스택에 추가
조치가 필요한 릴리스가 나왔을 때 주간 메일로 알려드립니다. 이번 릴리스의 보안 패치 같은 것들입니다.