Keycloak

Security & PrivacyApache-2.0

Open-source identity and access management.

Latest 26.7.3 · by Red HatWritten in JavaWebsitekeycloak/keycloakRSS

Release activity

Release activity — 11 releases across 11 days in the last year. Each cell is one day; darker means more releases that day. Older weeks are hidden at this screen width.
JunJulAugSep
SundayNo releases on May 24, 2026No releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026No releases on Aug 16, 2026No releases on Aug 23, 2026No releases on Aug 30, 2026No releases on Sep 6, 2026
MondayNo releases on May 25, 2026No releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026No releases on Aug 10, 2026No releases on Aug 17, 2026No releases on Aug 24, 20261 release on Aug 31, 2026No releases on Sep 7, 2026
TuesdayNo releases on May 26, 2026No releases on Jun 2, 2026No releases on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026No releases on Aug 11, 2026No releases on Aug 18, 2026No releases on Aug 25, 2026No releases on Sep 1, 2026No releases on Sep 8, 2026
WednesdayNo releases on May 27, 2026No releases on Jun 3, 2026No releases on Jun 10, 2026No releases on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 20261 release on Aug 5, 2026No releases on Aug 12, 20261 release on Aug 19, 2026No releases on Aug 26, 2026No releases on Sep 2, 2026
ThursdayNo releases on May 28, 20261 release on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 20261 release on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026No releases on Aug 13, 2026No releases on Aug 20, 2026No releases on Aug 27, 2026No releases on Sep 3, 2026
FridayNo releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 20261 release on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026No releases on Aug 14, 2026No releases on Aug 21, 2026No releases on Aug 28, 2026No releases on Sep 4, 2026
SaturdayNo releases on May 30, 2026No releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026No releases on Aug 8, 2026No releases on Aug 15, 2026No releases on Aug 22, 2026No releases on Aug 29, 2026No releases on Sep 5, 2026

11 releases in the last year

Changelog

26.7.3

Latest
Security 20
  • Fix LDAP client implementation certificate hostname verification
  • Fix required signed-JWT assertion policy bypass with unsigned assertion headers
  • Fix organization managers creating managed members through stored registration links without manage-users permission
  • Fix realm default-group reads disclosing hidden groups under FGAP v2
  • Fix missing per-role authorization on RoleContainerResource composite endpoints
  • Fix authorization codes being retargeted to another client session

From Keycloak

View originalPermalink
How 26.7.3 went

26.7.2

Changed 1
  • Upgrade to Quarkus 3.33.3.1
Fixed 11
  • Fixed password denylist false positive warning on startup with large pre-computed bloom file
  • Corrected SCIM name.formated field
  • Fixed rotated client secret remaining valid when the feature is disabled
  • Fixed invalid redirect URI on logout from pages with sub-tab hash fragments
  • Fixed parameterized UserPropertyMapper exposing target user attributes without permission check
  • Fixed passkey icons using wrong color variant when realm disables dark mode
Security 8
  • Fixed CVE-2026-45292 OpenTelemetry Java SDK unbounded memory allocation in W3C Baggage Propagation
  • Fixed CVE-2026-14613 fine-grained admin permissions bypass via role groups endpoint
  • Fixed CVE-2026-59888 and CVE-2026-59889 by upgrading jackson-databind to 2.21.5
  • Fixed CVE-2026-15945 group hierarchy search disclosure of hidden parent groups under fine-grained admin permissions v2
  • Fixed CVE-2026-17048 admin REST API leaking vault-resolved rotated client secrets
  • Fixed CVE-2026-15571 predictable account-linking hash enabling account takeover via malicious OIDC client
  • Fixed CVE-2026-18963 unauthenticated account takeover via reset-credentials flow bypass
  • Fixed show-config command printing vault keystore password in cleartext

From Keycloak

View originalPermalink
How 26.7.2 went

26.7.1

Fixed 4
  • Fix WebAuthn authenticator attachment policy being bypassed when the client omits the attachment field
  • Fix new password being committed when multiple password resets are detected
  • Fix 500 error when client requests organization scope with it already set to Default
  • Fix IllegalFormatConversionException in LiquibaseDBLockProviderFactory and wrong time conversion
Security 12
  • Fix JWE request object bypassing requestObjectSignatureAlg enforcement in OIDC
  • Fix privilege escalation via hardcoded role mapper injection in manage-clients
  • Fix user disclosure in Keycloak Admin UI Extension brute-force-user via search=id: under FGAP v2
  • Fix fine-grained admin permissions bypass in client scope assignment
  • Fix FGAP v2 parent group children endpoint bypassing per-child view permission filter
  • Fix authorization bypass via unnormalized uri matching in pathmatcher

From Keycloak

View originalPermalink
How 26.7.1 went

26.7.0

Added 9
  • Automate user provisioning with the SCIM API (preview)
  • Simplified multi-cluster high availability without external caches (preview)
  • Enhanced reverse proxy guides with blueprints for HAProxy and Traefik
  • Step-up authentication for SAML clients
  • Identity Brokering API V2 with client-level authorization, confidential client enforcement, OAuth 2.0 compliance, and session-based token storage
  • Attestation based client authentication (ABCA) experimental feature via client-auth-abca flag
Changed 1
  • Verifiable Credentials (OID4VCI) configuration is now fully configurable in the admin UI in addition to the admin REST API
Fixed 1
  • Multiple bugs fixed in Verifiable Credentials (OID4VCI) functionality with improved specification compliance
Deprecated 1
  • Identity Brokering API V1 is deprecated and will be removed in a future release

From Keycloak

View originalPermalink
How 26.7.0 went

26.6.4

Changed 1
  • Upgrade to Quarkus 3.33.2.1
Security 8
  • Fix group-admin escalation to realm-admin vulnerability
  • Fix information disclosure through arbitrary filesystem path probing vulnerability
  • Fix cross-site scripting (XSS) via case-insensitive URI validation bypass vulnerability
  • Fix attacker ability to re-enable and take over disabled clients via registration access token
  • Fix privilege escalation via improper scope mapping enforcement vulnerability
  • Fix unauthorized access to resources via UMA permission ticket bypass vulnerability
  • Fix policy enforcer authorization bypass via incorrect URI comparison vulnerability
  • Fix authentication bypass via JWT algorithm confusion vulnerability

From Keycloak

View originalPermalink
How 26.6.4 went

26.6.3

Fixed 4
  • Update UNSAFE_PATH_PATTERN regex to cover percent-encoded terminators and control characters
  • Fix NullPointerException in UMA permission grant when stale permission ticket references removed scope
  • Fix Account API Resource sharing endpoints to respect userManagedAccessAllowed realm setting
  • Fix Account resource sharing to resolve recipient by email before username to prevent granting access to wrong user
Security 16
  • Fix CVE-2026-4800 lodash vulnerability to Code Injection via _.template imports key names in account/ui
  • Fix CVE-2026-4874 Server-Side Request Forgery via OIDC token endpoint manipulation
  • Fix CVE-2026-37977 CORS Access-Control-Allow-Origin reflected from unverified JWT azp claim on UMA token endpoint
  • Fix CVE-2026-7500 Improper Access Control on Keycloak Server when the Account API feature is disabled
  • Fix CVE-2026-42581 Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
  • Fix CVE-2026-8922 OIDC token introspection ignores realm-level notBefore when client-level notBefore is set

From Keycloak

View originalPermalink
How 26.6.3 went

26.6.2

Changed 1
  • Upgrade to Quarkus 3.33.1.1
Fixed 3
  • Allow duplicate user attribute values to be removed
  • Account UI no longer reports error when opening an unknown path
  • Realm import with --import-realm no longer fails with ModelValidationException when Admin Permissions is enabled
Security 16
  • Fix HTTP/2 CONTINUATION Frame Flood Denial of Service (CVE-2026-33871)
  • Fix RFC violation HTTP Request Smuggling primitive via Chunked Extension Quoted-String Parsing (CVE-2026-33870)
  • Fix improper access control on Keycloak Server through UMA resource management endpoints via PUT parameters (CVE-2026-4628)
  • Fix stored XSS in select-organization.ftl with insufficient FreeMarker HTML-escape in inline JS handler (CVE-2026-4048)
  • Fix use of broken or risky cryptographic algorithm vulnerability in bcpkix modules (CVE-2026-5588)
  • Fix acceptable AAGUID policy bypass via packed self-attestation in WebAuthn registration (CVE-2026-6856)

From Keycloak

View originalPermalink
How 26.6.2 went

26.6.1

Added 1
  • Add database data at rest encryption
Changed 1
  • Update CloudNativePG to 1.29
Fixed 9
  • Fix false session type of access token in offline_access refresh token flow with scope parameter without offline_access scope
  • Fix Operator flood logs with warnings in v26.6.0
  • Fix inability to sync latest keycloak-admin-client to keycloak-client
  • Fix @keycloak/keycloak-admin-client installation failure in version 26.6.0
  • Fix invalid package reference in keycloak-admin-ui
  • Fix MigrateTo26_6_0 modifying custom browser flows and breaking existing realm authentication
Security 2
  • Fix CVE-2026-4366 Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling
  • Fix CVE-2026-4633 Keycloak user enumeration via identity-first login

From Keycloak

View originalPermalink
How 26.6.1 went

26.6.0

Added 9
  • JWT Authorization Grant enabling external-to-internal token exchange using externally signed JWT assertions
  • Federated client authentication allowing clients to leverage existing credentials and eliminate the need to manage individual client secrets in Keycloak
  • Workflows enabling administrators to automate realm administrative tasks such as user and client lifecycle management
  • Support for zero-downtime patch releases allowing rolling updates within a minor release stream without service downtime
  • Keycloak Test Framework replacing the previous Arquillian-based solution
  • New guide about Demonstrating Proof-of-Possession (DPoP) for OAuth 2.0 providing information on how to mitigate the risk of stolen tokens
Changed 2
  • JWT Authorization Grant promoted from preview to supported status
  • Federated client authentication promoted to supported status including support for client assertions issued by external OpenID Connect identity providers and Kubernetes Service Accounts

From Keycloak

View originalPermalink
How 26.6.0 went

26.5.7

Changed 1
  • Upgrade to Quarkus 3.27.3
Fixed 1
  • Fix uncaught error when call is made without Host header
Security 7
  • Fix improper access control in Admin REST API that leads to information disclosure
  • Fix static handler component cache manipulation vulnerability in vertx-core that can deny access to static files
  • Fix improper access control for level of assurance during credential deletion in account API
  • Fix application-level denial of service vulnerability via scope processing
  • Fix UMA policy resource injection vulnerability that allows unauthorized cross-user permission grants
  • Fix redirect URI validation bypass via path traversal in OIDC auth endpoint
  • Fix privilege escalation vulnerability via forged authorization codes due to SingleUseObjectProvider isolation flaw

From Keycloak

View originalPermalink
How 26.5.7 went

26.5.6

Fixed 10
  • Fix federated user disabled when external DB unavailable never re-enabled
  • Fix AUTH_SESSION_ID cookie reuse causes cross-user session contamination on re-authentication
  • Fix UsersResource.search briefRepresentation started to return user attributes
  • Fix unexpected error when logging out with offline session and external IDP
  • Fix operator-built DB config targetServerType=primary not applied and connection validation not working after master-replica failover
  • Fix partial LDAP sync duration does not follow the defined value in user federation
Security 8
  • Fix Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri
  • Fix Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition
  • Fix Keycloak IDOR in realm client creating/deleting
  • Fix Keycloak Admin REST API Improper Access Control leads to sensitive role metadata information disclosure
  • Fix privilege escalation via manage-clients permission
  • Fix information disclosure via improper role enforcement in UMA 2.0 Protection API
  • Fix information disclosure of disabled user attributes via administrative endpoint
  • Fix authorization bypass allowing unprivileged tokens to enumerate user organization memberships

From Keycloak

View originalPermalink
How 26.5.6 went
View all

Discussion

If you publish Keycloak, you can claim this product by proving you administer its repository.