Keycloak 26.6.3

26.6.3
Fixed 4
  • Update UNSAFE_PATH_PATTERN regex to cover percent-encoded terminators and control characters
  • Fix NullPointerException in UMA permission grant when stale permission ticket references removed scope
  • Fix Account API Resource sharing endpoints to respect userManagedAccessAllowed realm setting
  • Fix Account resource sharing to resolve recipient by email before username to prevent granting access to wrong user
Security 16
  • Fix CVE-2026-4800 lodash vulnerability to Code Injection via _.template imports key names in account/ui
  • Fix CVE-2026-4874 Server-Side Request Forgery via OIDC token endpoint manipulation
  • Fix CVE-2026-37977 CORS Access-Control-Allow-Origin reflected from unverified JWT azp claim on UMA token endpoint
  • Fix CVE-2026-7500 Improper Access Control on Keycloak Server when the Account API feature is disabled
  • Fix CVE-2026-42581 Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
  • Fix CVE-2026-8922 OIDC token introspection ignores realm-level notBefore when client-level notBefore is set
View original

Upgraded? How did it go?

Discussion