Keycloak Changelog
Keycloak — Security, Auth product updates and releases, tracked on megachangelog.
Keycloak 26.7.0 Release
Keycloak 26.7.0 introduces SCIM API for user provisioning automation, multi-cluster high availability without external caches, enhanced reverse proxy guides, step-up authentication for SAML clients, and major security improvements including a new Identity Brokering API V2 with client-level authorization. Verifiable Credentials (OID4VCI) continues development with better UI configuration and spec compliance.
26.6.4 Release
Keycloak 26.6.4 addresses eight critical security vulnerabilities including privilege escalation, authentication bypass, cross-site scripting, and authorization bypass issues. The release also upgrades to Quarkus 3.33.2.1 and fixes several bugs related to CI, migration documentation, and project build.
Review permission model to access SCIM APIs
Changed access requirements for SCIM API endpoints ServiceProviderConfig, ResourceTypes, and Schemas to require only query-users or query-groups permissions instead of more restrictive access controls.
Keycloak 26.6.3 Security and Bug Fix Release
This release addresses 14 critical and high-severity CVEs covering OIDC token handling, WebAuthn validation, CORS bypass, SSRF vulnerabilities, and privilege escalation issues. Additionally, it includes multiple bug fixes for core functionality and enhancements to Quarkus and dependencies.
Keycloak 26.6.2
Keycloak 26.6.2 is a patch release that includes 16 critical security fixes addressing CVEs related to HTTP/2 CONTINUATION frame floods, HTTP request smuggling, improper access control in UMA endpoints, stored XSS vulnerabilities, WebAuthn attestation bypasses, and various authentication and token handling vulnerabilities. Also includes bug fixes and enhancements to monitoring, installation documentation, and Quarkus upgrade to 3.33.1.1.
Version 26.4.12 released
Keycloak 26.4.12 has been released with version-specific updates and improvements.
Version 26.2.16 released
Keycloak version 26.2.16 has been released with various updates and improvements.
Keycloak 26.6.1
This release addresses two critical security vulnerabilities including a blind SSRF via HTTP redirect handling and user enumeration via identity-first login. It also includes bug fixes for session token handling, admin client installation issues, and various other stability improvements.
Keycloak 26.6.0 released with JWT Grant, Federated Auth, and Workflows
Keycloak 26.6.0 promotes JWT Authorization Grant, Federated Client Authentication, and Workflows from preview to fully supported, enabling external token exchange, credential federation without managing secrets, and realm automation. The release also adds Organization Groups, DPoP guidance, Identity Brokering APIs V2, step-up SAML authentication, and LDAP password policy enforcement.
Keycloak 26.5.7
Security update addressing seven CVEs including improper access control in Admin REST API, UMA policy injection vulnerabilities, OIDC redirect URI validation bypass, and privilege escalation via forged authorization codes. Also includes upgrade to Quarkus 3.27.3 and a bug fix for Host header handling.
Sign up to see more
13 more changes from Keycloak. Sign up to read the whole changelog.
Sign up freeGitHub or email — no card needed.