megachangelog
Security26.7.2

Keycloak 26.7.2 release

Keycloak 26.7.2 includes multiple critical security fixes addressing CVEs in OpenTelemetry, jackson-databind, fine-grained admin permissions, account linking, and credential reset flows, plus bug fixes and enhancements including a Quarkus upgrade.

Upgrading

Before upgrading refer to the migration guide for a complete list of changes.

All resolved issues

Security fixes

Weaknesses

  • #50844 show-config prints the vault keystore password in cleartext dist/quarkus

Enhancements

  • #51344 Upgrade to Quarkus 3.33.3.1

Bugs

  • #50751 Password denylist: false fpp warning on startup with large pre-computed .bloom file authentication
  • #50849 Correct SCIM name.formated scim
  • #50855 Rotated client secret remains valid when the feature is disabled oidc
  • #51054 Invalid redirect URI on logout from pages with sub-tab hash fragments admin/ui
  • #51061 Parameterized UserPropertyMapper exposes target user attributes without permission check core
  • #51087 Passkey icons use wrong color variant when realm disables dark mode authentication/webauthn
  • #51088 Verify email not working in incognito browser tab after Keycloak restart authentication
  • #51131 Warning "Proactive closing of the session was missed - refinements are needed to TransactionSessionHandler related logic" appears core
  • #51154 Upgrade to 26.7.0 fails with preview features as the stateless cluster provider captures a null NodeInfo before postInit infinispan
  • #51164 WebAuthn tests are being skipped in Github workflows workflows
  • #51182 Large HTTP/2 request headers are rejected with a bare 500 and no log; same request works over HTTP/1.1 dist/quarkus
  • #51323 Custom realm-level role named admin cannot be updated in non-master realms after Keycloak 26.7.0 admin/rbac
  • #51331 Adding org member fails with 500 with stateless:v1 feature enabled organizations
  • #51407 The dist for Java API docs is empty docs
  • #51449 Incorrect query parameter name for "max"
  • #51476 Invalid link for https://www.ietf.org/rfc/rfc4559.txt docs
securitybugfixoidcauthenticationadmin

Source: original entry ↗