<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Keycloak - Package Updates]]></title><description><![CDATA[<p dir="auto"><strong>You can use this thread to track updates to the Keycloak package.</strong></p>
<p dir="auto">Please open issues in a separate topic instead of replying here.</p>
]]></description><link>https://forum.cloudron.io/topic/13214/keycloak-package-updates</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Apr 2026 12:46:13 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/13214.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 30 Jan 2025 17:23:17 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Keycloak - Package Updates on Thu, 09 Apr 2026 10:01:50 GMT]]></title><description><![CDATA[<p dir="auto">[1.6.0]</p>
<ul>
<li>Update keycloak to 26.6.0</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.6.0" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>JWT Authorization Grant, enabling external-to-internal token exchange using externally signed JWT assertions.</li>
<li>Federated client authentication, eliminating the need to manage individual client secrets in Keycloak.</li>
<li>Workflows, enabling administrators to automate realm administrative tasks such as user and client lifecycle management.</li>
<li>Zero-downtime patch releases, allowing rolling updates within a minor release stream without service downtime.</li>
<li>The Keycloak Test Framework, replacing the previous Arquillian-based solution.</li>
<li>JWT Authorization Grant (supported)</li>
<li>Federated client authentication (supported)</li>
<li>New guide about Demonstrating Proof-of-Possession (DPoP)</li>
<li>Identity Brokering APIs V2 (preview)</li>
<li>Step-up authentication for SAML (preview)</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/123111</link><guid isPermaLink="true">https://forum.cloudron.io/post/123111</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 09 Apr 2026 10:01:50 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Thu, 02 Apr 2026 15:23:38 GMT]]></title><description><![CDATA[<p dir="auto">[1.5.7]</p>
<ul>
<li>Update keycloak to 26.5.7</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.5.7" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
</ul>
]]></description><link>https://forum.cloudron.io/post/122845</link><guid isPermaLink="true">https://forum.cloudron.io/post/122845</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 02 Apr 2026 15:23:38 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Fri, 20 Mar 2026 07:28:18 GMT]]></title><description><![CDATA[<p dir="auto">[1.5.6]</p>
<ul>
<li>Update keycloak to 26.5.6</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.5.6" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>CVE-2026-1180 - Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri oidc</li>
<li>CVE-2026-1035 - Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition oidc</li>
<li>CVE-2025-14777 - Keycloak IDOR in realm client creating/deleting</li>
<li>CVE-2025-14082 keycloak-server: Keycloak Admin REST API: Improper Access Control leads to sensitive role metadata information disclosure</li>
<li>CVE-2026-3121 - Keycloak: Privilege escalation via manage-clients permission</li>
<li>CVE-2026-3190 - Information Disclosure via improper role enforcement in UMA 2.0 Protection API core</li>
<li>CVE-2026-3911 Keycloak: Information disclosure of disabled user attributes via administrative endpoint user-profile</li>
<li>CVE-2026-2366 Authorization Bypass: Unprivileged tokens can enumerate user organization memberships organizations</li>
<li>Federated user disabled when external DB unavailable, never re-enabled storage</li>
<li>AUTH_SESSION_ID cookie reuse causes cross-user session contamination on re-authentication authentication</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/122204</link><guid isPermaLink="true">https://forum.cloudron.io/post/122204</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Fri, 20 Mar 2026 07:28:18 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Fri, 06 Mar 2026 03:08:02 GMT]]></title><description><![CDATA[<p dir="auto">[1.5.5]</p>
<ul>
<li>Update keycloak to 26.5.5</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.5.5" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>&lt;a href="<a href="https://github.com/keycloak/keycloak/issues/46909" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/keycloak/keycloak/issues/46909</a>"&gt;#​46909&lt;/a&gt; CVE-2026-3047 SAML broker: Authentication bypass due to disabled SAML client completing IdP-initiated login &lt;/li&gt;</li>
<li>&lt;a href="<a href="https://github.com/keycloak/keycloak/issues/46910" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/keycloak/keycloak/issues/46910</a>"&gt;#​46910&lt;/a&gt; CVE-2026-3009 Improper Enforcement of Disabled Identity Provider in IdentityBrokerService &lt;/li&gt;</li>
<li>&lt;a href="<a href="https://github.com/keycloak/keycloak/issues/46911" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/keycloak/keycloak/issues/46911</a>"&gt;#​46911&lt;/a&gt; CVE-2026-2603 Disabled SAML IdP still allows IdP-initiated broker login &lt;/li&gt;</li>
<li>&lt;a href="<a href="https://github.com/keycloak/keycloak/issues/46912" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/keycloak/keycloak/issues/46912</a>"&gt;#​46912&lt;/a&gt; CVE-2026-2092 saml broker encrypted assertion injection &lt;/li&gt;</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/121319</link><guid isPermaLink="true">https://forum.cloudron.io/post/121319</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Fri, 06 Mar 2026 03:08:02 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Fri, 20 Feb 2026 14:03:01 GMT]]></title><description><![CDATA[<p dir="auto">[1.5.4]</p>
<ul>
<li>Update keycloak to 26.5.4</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.5.4" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>CVE-2026-1190 - Keycloak SAML brokering: Response delay due to unchecked NotOnOrAfter in SubjectConfirmationData saml</li>
<li>CVE-2026-0707: Keycloak Authorization Header Parsing Leading to Potential Security Control Bypass</li>
<li>CVE-2025-5416 keycloak-core: Keycloak Environment Information</li>
<li>CVE-2026-2575 - Denial of Service due to excessive SAMLRequest decompression saml</li>
<li>CVE-2026-2733 Missing Check on Disabled Client for Docker Registry Protocol</li>
<li>New key affinity for session ids</li>
<li>"Update email" AIA: "Back to Application" URL invokes OIDC callback with missing parameters oidc</li>
<li>Client deletion timeout due to large number of client roles storage</li>
<li>auth_mellon (SAML) authentication fails after upgrade to 26.5.1 (from 26.4.6) saml</li>
<li>Information Disclosure of Client Secret on Unauthenticated Config Endpoint oidc</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/120513</link><guid isPermaLink="true">https://forum.cloudron.io/post/120513</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Fri, 20 Feb 2026 14:03:01 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Wed, 11 Feb 2026 10:05:41 GMT]]></title><description><![CDATA[<p dir="auto">[1.5.3]</p>
<ul>
<li>Update keycloak to 26.5.3</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.5.3" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li><a href="https://github.com/keycloak/keycloak/issues/46144" target="_blank" rel="noopener noreferrer nofollow ugc">46144</a> CVE-2026-1609 Disabled users can still obtain tokens via JWT Authorization Grant</li>
<li><a href="https://github.com/keycloak/keycloak/issues/46145" target="_blank" rel="noopener noreferrer nofollow ugc">46145</a> CVE-2026-1529 Forged invitation JWT enables cross-organization self-registration</li>
<li><a href="https://github.com/keycloak/keycloak/issues/46146" target="_blank" rel="noopener noreferrer nofollow ugc">46146</a> CVE-2026-1486 Logic Bypass in JWT Authorization Grant Allows Authentication via Disabled Identity Providers</li>
<li><a href="https://github.com/keycloak/keycloak/issues/46147" target="_blank" rel="noopener noreferrer nofollow ugc">46147</a> CVE-2025-14778 Incorrect ownership checks in /uma-policy/</li>
<li><a href="https://github.com/keycloak/keycloak/issues/45892" target="_blank" rel="noopener noreferrer nofollow ugc">45892</a> Upgrade minikube for CI tests <code>operator</code></li>
<li><a href="https://github.com/keycloak/keycloak/issues/44379" target="_blank" rel="noopener noreferrer nofollow ugc">44379</a> Node.js admin client does not refresh tokens <code>admin/client-js</code></li>
<li><a href="https://github.com/keycloak/keycloak/issues/45459" target="_blank" rel="noopener noreferrer nofollow ugc">45459</a> k8s multiple restart (oomkilled) in v26.5.0-0 during startup because of RAM <code>dist/quarkus</code></li>
<li><a href="https://github.com/keycloak/keycloak/issues/45662" target="_blank" rel="noopener noreferrer nofollow ugc">45662</a> Increase in startup memory consumption in post 26.5 versions <code>dist/quarkus</code></li>
<li><a href="https://github.com/keycloak/keycloak/issues/45677" target="_blank" rel="noopener noreferrer nofollow ugc">45677</a> Hibernate Validator is enabled by default when not used <code>dist/quarkus</code></li>
<li><a href="https://github.com/keycloak/keycloak/issues/45708" target="_blank" rel="noopener noreferrer nofollow ugc">45708</a> Unpexted value '' in mixed-cluster-compatibility-tests <code>testsuite</code></li>
</ul>
]]></description><link>https://forum.cloudron.io/post/120029</link><guid isPermaLink="true">https://forum.cloudron.io/post/120029</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Wed, 11 Feb 2026 10:05:41 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Fri, 23 Jan 2026 16:45:27 GMT]]></title><description><![CDATA[<p dir="auto">[1.5.2]</p>
<ul>
<li>Update keycloak to 26.5.2</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.5.2" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>#​44994 CVE-2025-67735 - netty-codec-http: Request Smuggling via CRLF Injection dependencies</li>
<li>#​43443 Keycloak should warn when ISPN or JGROUPS is running in debug level logging</li>
<li>#​45498 Ignore OpenAPI artifacts when disabled dist/quarkus</li>
<li>#​44785 Can not get through SSO login if using a custom attribute with default value user-profile</li>
<li>#​45015 Deadlock in Infinispan virtual threads infinispan</li>
<li>#​45250 IDToken contains duplicate address claims oidc</li>
<li>#​45333 User admin events don't show role, group mapping, reset password like events admin/ui</li>
<li>#​45396 Database Migration fails when updating to 26.5.0 on MS SQL core</li>
<li>#​45415 cache-remote-host becomes mandatory at build time when using clusterless feature infinispan</li>
<li>#​45417 Unmanaged Attributes Type (Only administrators can view) allows admin API to set Unmanaged Attributes user-profile</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/119048</link><guid isPermaLink="true">https://forum.cloudron.io/post/119048</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Fri, 23 Jan 2026 16:45:27 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Wed, 14 Jan 2026 20:54:55 GMT]]></title><description><![CDATA[<p dir="auto">[1.5.1]</p>
<ul>
<li>Update keycloak to 26.5.1</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.5.1" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>#​44863 x-robots HTTP header missing for static Keycloak resources, and REST endpoint responses</li>
<li>#​45009 Performance improvement: Missing indexes on BROKER_LINK table columns</li>
<li>#​45182 Allow full managing of realms from master realm without global admin role</li>
<li>#​43975 Test Framework -&gt; Embedded server -&gt; Maven execution failure: Failed to read script file from: scripts/default-policy.js &lt;code&gt;test-framework&lt;/code&gt;</li>
<li>#​44371 403 Forbidden when assigning realm-management client roles despite FGAP disabled (regression in 26.4.0+) &lt;code&gt;admin/fine-grained-permissions&lt;/code&gt;</li>
<li>#​44417 Security issue with Organization feature exposes and fills the account name automatically in user/password form &lt;code&gt;organizations&lt;/code&gt;</li>
<li>#​44783 Create Realm button is missing when user has create-realm role &lt;code&gt;admin/ui&lt;/code&gt;</li>
<li>#​44860 Admin UI: slow response time listing second user page &lt;code&gt;admin/ui&lt;/code&gt;</li>
<li>#​45003 Bug in JWTClientAuthenticator and JWTClientSecretAuthenticator causes NPE &lt;code&gt;authentication&lt;/code&gt;</li>
<li>#​45093 Enable visibility of Role Mapping tab for users with view-users role &lt;code&gt;admin/ui&lt;/code&gt;</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/118530</link><guid isPermaLink="true">https://forum.cloudron.io/post/118530</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Wed, 14 Jan 2026 20:54:55 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Tue, 06 Jan 2026 08:52:38 GMT]]></title><description><![CDATA[<p dir="auto">[1.5.0]</p>
<ul>
<li>Update keycloak to 26.5.0</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.5.0" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>Workflows to automate administrative tasks and process within a realm.</li>
<li>JWT Authorization Grants, our recommended alternative to external to internal token exchange.</li>
<li>Guide for using Keycloak as an authorization server for Model Context Protocol (MCP) servers.</li>
<li>Authenticating clients with Kubernetes service account tokens to avoid static client secrets.</li>
<li>OpenTelemetry support for metrics and logging, combining all observability information in this popular standard.</li>
<li>CORS (Cross Origin Resource Sharing) is a browser security feature that controls how web pages on one domain can request resources from a different domain.</li>
<li>For the OpenID Connect Dynamic Client Registration, you can now specify which CORS headers are allowed via the client registration access policies.</li>
<li>For the overall CORS configuration, you can now allow environment specific headers to be allowed using the SPI option spi-cors--default--allowed-headers.</li>
<li>The client logout configuration now includes an option to show a logout confirmation page. When enabled, users will see a You are logged out confirmation page upon successful logout.</li>
<li>Previously, all scopes of an OpenID Connect client were advertised in the discovery endpoint.</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/117995</link><guid isPermaLink="true">https://forum.cloudron.io/post/117995</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Tue, 06 Jan 2026 08:52:38 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Tue, 02 Dec 2025 08:14:37 GMT]]></title><description><![CDATA[<p dir="auto">[1.4.6]</p>
<ul>
<li>Update keycloak to 26.4.7</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.4.7" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>#43156 [Docs] Warn users about printing headers in HTTP access logs docs</li>
<li>#43643 Upgrade to Quarkus 3.27.1 dist/quarkus</li>
<li>#44438 Intermittent ConcurrentModificationException during SAML initialization causing status code 400 for clients saml</li>
<li>#44480 Wrong persistent group permissions when multiple group membership changes happen in the same request core</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/116333</link><guid isPermaLink="true">https://forum.cloudron.io/post/116333</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Tue, 02 Dec 2025 08:14:37 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Wed, 26 Nov 2025 07:32:15 GMT]]></title><description><![CDATA[<p dir="auto">[1.4.5]</p>
<ul>
<li>Update keycloak to 26.4.6</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.4.6" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>This release adds filtering of LDAP referrals by default.</li>
<li>#43323 Sessions not removed when user is deleted infinispan</li>
<li>#43738 UPDATE_EMAIL action invalidates old email login/ui</li>
<li>#43812 Admin console sends non-JSON payload with content-type: application/json admin/ui</li>
<li>#44125 Double-encoding of query parameter values (e.g. acr_values) for version 26.4 identity-brokering</li>
<li>#44189 [jdbc-ping] SQLIntegrityConstraintViolationException: Duplicate entry infinispan</li>
<li>#44229 Unexpected FORMAT_FAILURE error when using cache-config-file with feature-disabled=persistent-user-sessions infinispan</li>
<li>#44269 Admin Client creates malformed paths for requests admin/client-js</li>
<li>#44287 Caching of static theme resources in dev mode is disabled core</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/116024</link><guid isPermaLink="true">https://forum.cloudron.io/post/116024</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Wed, 26 Nov 2025 07:32:15 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Thu, 13 Nov 2025 08:04:38 GMT]]></title><description><![CDATA[<p dir="auto">[1.4.4]</p>
<ul>
<li>Update keycloak to 26.4.5</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.4.5" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>#​43564 Invalid liquibase check sum for jpa-changelog-2.5.0.xml &lt;code&gt;core&lt;/code&gt;</li>
<li>#​43718 Email Not Persisted During Registration When "Email as Username" is Enabled and User Edit Permission is Disabled &lt;code&gt;user-profile&lt;/code&gt;</li>
<li>#​43793 import does not seem to run db migration &lt;code&gt;import-export&lt;/code&gt;</li>
<li>#​43883 Creating group policy on a client uses "manage-clients" role if FGAP V1 is disabled &lt;code&gt;authorization-services&lt;/code&gt;</li>
<li>#​44010 Ordering attributes will unset the unmanaged attribute policy &lt;code&gt;user-profile&lt;/code&gt;</li>
<li>#​44031 Can't build  keycloak 26.4.4 with quarkus.launch.rebuild=true &lt;code&gt;dist/quarkus&lt;/code&gt;</li>
<li>#​44056 Allow only normalized URLs in requests caused a regression in view authz permission details in Admin Consol &lt;code&gt;admin/ui&lt;/code&gt;</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/115310</link><guid isPermaLink="true">https://forum.cloudron.io/post/115310</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 13 Nov 2025 08:04:38 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Sat, 08 Nov 2025 07:57:16 GMT]]></title><description><![CDATA[<p dir="auto">[1.4.3]</p>
<ul>
<li>Update keycloak to 26.4.4</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.4.4" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>#10388 Allow to hide client scopes from scopes_supported in discovery endpoint</li>
<li>#43076 Add rate limiter for sending verification emails in context of update email</li>
<li>#43509 Role authorization for workflows. <code>admin/api</code></li>
<li>#41270 Cannot save new attribute group <code>admin/ui</code></li>
<li>#41271 Changing user profile attribute results in an error everytime <code>admin/ui</code></li>
<li>#43082 ExternalLinksTest is broken due to missing path parameters <code>docs</code></li>
<li>#43091 Duplicate Email Fields on Temporarily Locked Out Sign In With Organization Identity-First Login <code>login/ui</code></li>
<li>#43160 Regression in DEBUG_PORT handling since 26.4.0  host binding (*:port / 0.0.0.0:port) no longer works <code>dist/quarkus</code></li>
<li>#43460 FGAP/UI: <code>reset-password</code> succeeds but UI shows 403 without Users:manage <code>admin/fine-grained-permissions</code></li>
<li>#43505 DPoP proof replay check doesn't consider clock skew <code>oidc</code></li>
</ul>
]]></description><link>https://forum.cloudron.io/post/115050</link><guid isPermaLink="true">https://forum.cloudron.io/post/115050</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Sat, 08 Nov 2025 07:57:16 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Fri, 24 Oct 2025 07:54:37 GMT]]></title><description><![CDATA[<p dir="auto">[1.4.2]</p>
<ul>
<li>Update keycloak to 26.4.2</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.4.2" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>#43351 Make pending email verification attribute removable by admin user-profile</li>
<li>#43650 SPIFFE should support OIDC JWK endpoint</li>
<li>#30939 Vulnerability in brute force detection settings authentication</li>
<li>#43022 Incorrect Basic Auth encoding for OIDC IDentity Provider when Client ID contains colon identity-brokering</li>
<li>#43244 UI crash on admin <code>/users/add-user</code> since 26.4.0 admin/ui</li>
<li>#43561 Server does not shutdown gracefully when started with --optimized core</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/114361</link><guid isPermaLink="true">https://forum.cloudron.io/post/114361</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Fri, 24 Oct 2025 07:54:37 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Thu, 16 Oct 2025 17:09:51 GMT]]></title><description><![CDATA[<p dir="auto">[1.4.1]</p>
<ul>
<li>Update keycloak to 26.4.1</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.4.1" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>#​43020 Secure Client-Initiated Renegotiation - disable by default <code>dist/quarkus</code></li>
<li>#​42990 Hide read-only email attribute in update profile context with update email enabled <code>user-profile</code></li>
<li>#​43357 JDBC_PING should publish its physical address on startup</li>
<li>#​40965 Group permission denies to view user <code>admin/fine-grained-permissions</code></li>
<li>#​41292 openid-connect flow is missing response type on language change <code>authentication</code></li>
<li>#​42565 Standard Token Exchange: chain of exchanges eventually fails <code>token-exchange</code></li>
<li>#​42676 Security Defenses realm settings lost when switching between Headers and Brute Force Detection tabs (v25+) <code>admin/ui</code></li>
<li>#​42907 Race condition in authorization service leads to NullPointerException when evaluating permissions during concurrent resource deletion <code>authorization-services</code></li>
<li>#​43042 Avoid NPE in FederatedJWTClientAuthenticator when checking for supported assertion types <code>core</code></li>
<li>#​43070 Update email page with pending verification email messages prefilled with old email <code>user-profile</code></li>
</ul>
]]></description><link>https://forum.cloudron.io/post/113923</link><guid isPermaLink="true">https://forum.cloudron.io/post/113923</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 16 Oct 2025 17:09:51 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Wed, 01 Oct 2025 00:39:00 GMT]]></title><description><![CDATA[<p dir="auto">[1.4.0]</p>
<ul>
<li>Update keycloak to 26.4.0</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.4.0" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>Passkeys for seamless, passwordless authentication of users.</li>
<li>Federated Client Authentication to use SPIFFE or Kubernetes service account tokens for client authentication.</li>
<li>Simplified deployments across multiple availability zones to boost availability.</li>
<li>FAPI 2 Final: Keycloak now supports the final specifications of FAPI 2.0 Security Profile and FAPI 2.0 Message Signing.</li>
<li>DPoP: The OAuth 2.0 Demonstrating Proof-of-Possession at the Application Layer (DPoP) is now fully supported. Improvements include the ability to bind only refresh tokens for public clients, and securing all Keycloak endpoints with DPoP tokens.</li>
<li>FIPS 140-2 mode now supports EdDSA</li>
<li>Listing supported OAuth standards on one page</li>
<li>Automatic certificate management for SAML clients</li>
<li>Update Email Workflow (supported)</li>
<li>Optional email domain for organizations</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/113203</link><guid isPermaLink="true">https://forum.cloudron.io/post/113203</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Wed, 01 Oct 2025 00:39:00 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Thu, 25 Sep 2025 07:49:19 GMT]]></title><description><![CDATA[<p dir="auto">[1.3.5]</p>
<ul>
<li>Update keycloak to 26.3.5</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.3.5" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
</ul>
]]></description><link>https://forum.cloudron.io/post/112968</link><guid isPermaLink="true">https://forum.cloudron.io/post/112968</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 25 Sep 2025 07:49:19 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Sat, 13 Sep 2025 12:29:55 GMT]]></title><description><![CDATA[<p dir="auto">[1.3.4]</p>
<ul>
<li>Update keycloak to 26.3.4</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.3.4" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>#​40630 Double check when working with multithreading. SAST</li>
<li>#​42245 Upgrade to Quarkus 3.20.2.2</li>
<li>#​35825 Per client session idle time capped by realm level client idle timeout core</li>
<li>#​40374 Random but frequent duplicate key value violates unique constraint "constraint_offl_us_ses_pk2" errors authentication</li>
<li>#​40463 Login to Account Console produces two consecutive LOGIN events account/ui</li>
<li>#​40857 Unbounded login_hint Parameter Can Corrupt KC_RESTART Cookie and Break Login Flow oidc</li>
<li>#​41427 Parallel token exchange fails if client session is expired token-exchange</li>
<li>#​41801 Lack of coordination in database creation in 26.3.0 causes deployment failures (Reopen) core</li>
<li>#​41942 Uncaught server error: org.keycloak.models.ModelException: Database operation failed : Sync LDAP Groups to Keycloak (Custom Provider) core</li>
<li>#​42012 Client session timestamp not updated in the database if running multiple nodes infinispan</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/112657</link><guid isPermaLink="true">https://forum.cloudron.io/post/112657</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Sat, 13 Sep 2025 12:29:55 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Thu, 21 Aug 2025 07:54:15 GMT]]></title><description><![CDATA[<p dir="auto">[1.3.3]</p>
<ul>
<li>Update keycloak to 26.3.3</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.3.3" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>#​39562 Breaking template change: Unknown <code>locale</code> input field added to user-profile registration page &lt;code&gt;user-profile&lt;/code&gt;</li>
<li>#​40984 Backchannel logout token with an unexpected signature algorithm key &lt;code&gt;oidc&lt;/code&gt;</li>
<li>#​41023 Can't send e-mails to international e-mail addresses: bad UTF-8 syntax &lt;code&gt;core&lt;/code&gt;</li>
<li>#​41098 Locked out after upgrade to 26.3.1 due to missing sub in lightweight access token &lt;code&gt;core&lt;/code&gt;</li>
<li>#​41268 <code>--optimized</code> flag and providers jar are incompatible when used with tools changing <code>last-modify-date</code> &lt;code&gt;dist/quarkus&lt;/code&gt;</li>
<li>#​41290 Concurrent starts with JDBC_PING lead to a split cluster &lt;code&gt;infinispan&lt;/code&gt;</li>
<li>#​41390 JDBC_PING2 doesn't merge split clusters after a while &lt;code&gt;infinispan&lt;/code&gt;</li>
<li>#​41421 Broken link securing-cache-communication in caching docs &lt;code&gt;docs&lt;/code&gt;</li>
<li>#​41423 Duplicate IDs in generated all configuration docs &lt;code&gt;docs&lt;/code&gt;</li>
<li>#​41469 Uncaught exception cases unclosed spans in tracing &lt;code&gt;dist/quarkus&lt;/code&gt;</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/111870</link><guid isPermaLink="true">https://forum.cloudron.io/post/111870</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 21 Aug 2025 07:54:15 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Fri, 25 Jul 2025 13:25:54 GMT]]></title><description><![CDATA[<p dir="auto">[1.3.2]</p>
<ul>
<li>Update keycloak to 26.3.2</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.3.2" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>#40237 Add option "Requires short state parameter" to OIDC IDP authentication</li>
<li>#40970 Run clustering compatibility tests on release/x.y branches</li>
<li>#41034 Improve logging for client sessions load</li>
<li>#41257 Upgrade to Infinispan 15.0.18.Final infinispan</li>
<li>#39634 Update MariaDB connector to 3.5.3 dist/quarkus</li>
<li>#40553 Upgrade org.postgresql:postgresql to version 42.7.7 to address CVE-2025-49146 dependencies</li>
<li>#40736 CVE-2025-49574 - Exposure of Resource to Wrong Sphere vulnerability in io.vertx:vertx-core dependencies</li>
<li>#40784 Default jdbc-ping cluster setup for distributed caches fails in Oracle infinispan</li>
<li>#40980 Can't update security-admin-console via admin UI with volatile sessions infinispan</li>
<li>#40995 LDAP /  ModelException: At least one condition should be provided to OR query core</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/110691</link><guid isPermaLink="true">https://forum.cloudron.io/post/110691</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Fri, 25 Jul 2025 13:25:54 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Thu, 10 Jul 2025 07:23:25 GMT]]></title><description><![CDATA[<p dir="auto">[1.3.1]</p>
<ul>
<li>Update keycloak to 26.3.1</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.3.1" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
</ul>
]]></description><link>https://forum.cloudron.io/post/109955</link><guid isPermaLink="true">https://forum.cloudron.io/post/109955</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 10 Jul 2025 07:23:25 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Fri, 04 Jul 2025 07:20:28 GMT]]></title><description><![CDATA[<p dir="auto">[1.3.0]</p>
<ul>
<li>Update keycloak to 26.3.0</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.3.0" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>Account recovery with 2FA recovery codes, protecting users from lockout.</li>
<li>Simplified experiences for application developers with streamlined WebAuthn/Passkey registration and simplified account linking to identity providers via application initiated actions.</li>
<li>Broader connectivity with the ability to broker with any OAuth 2.0 compliant authorization server, and enhanced trusted email verification for OpenID Connect providers.</li>
<li>Asynchronous logging for higher throughput and lower latency, ensuring more efficient deployments.</li>
<li>For administrators, experimental rolling updates for patch releases mean minimized downtime and smoother upgrades.</li>
<li>The custom protocol, which was previously used for client-initiated account linking, is now deprecated.</li>
<li>#21995 Configurable probes in the Operator operator</li>
<li>#29116 Add supported config options for additional datasources dist/quarkus</li>
<li>#29596 Passkeys conditional UI: integration with username/password form authentication/webauthn</li>
<li>#38465 Name for OTP device should be unique account/api</li>
<li>#38985 Possibility to log details and representation to the jboss-logging listener</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/109662</link><guid isPermaLink="true">https://forum.cloudron.io/post/109662</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Fri, 04 Jul 2025 07:20:28 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Wed, 28 May 2025 09:23:46 GMT]]></title><description><![CDATA[<p dir="auto">[1.2.5]</p>
<ul>
<li>Update keycloak to 26.2.5</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.2.5" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>Fix Securing Apps links to adapters docs</li>
<li>Email server credentials can be harvested through host/port manipulation admin/api</li>
<li>Fix doc link to FGAP v1 docs</li>
<li>Apply edits to Operators Guide docs</li>
<li>Edit Observability Guide docs</li>
<li>Fix callouts in Operator guide docs</li>
<li>Sessions from Infinispan should be mapped lazily for the Admin UI</li>
<li>Speed up Infinispan list of all sessions be more eagerly remove old client sessions</li>
<li>When logging in, all client sessions are loaded which is slow oidc</li>
<li>Authorization Code Flow Fails Scope Validation After Credential Definition Migration to Realm Level oid4vc</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/107823</link><guid isPermaLink="true">https://forum.cloudron.io/post/107823</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Wed, 28 May 2025 09:23:46 GMT</pubDate></item><item><title><![CDATA[Reply to Keycloak - Package Updates on Fri, 09 May 2025 07:21:03 GMT]]></title><description><![CDATA[<p dir="auto">[1.2.4]</p>
<ul>
<li>Update keycloak to 26.2.4</li>
<li><a href="https://github.com/keycloak/keycloak/releases/tag/26.2.4" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>#35278 Double click on social provider link causes page has expired error &lt;code&gt;login/ui&lt;/code&gt;</li>
<li>#39021 After migrating to newer Keycloak, token refreshes using inherited offline sessions return access tokens with invalid exp value &lt;code&gt;oidc&lt;/code&gt;</li>
<li>#39023 Keycloak 26.2.0 UI Performance Degradation &lt;code&gt;admin/ui&lt;/code&gt;</li>
<li>#39173 duplicate key value violates unique constraint "constraint_offl_cl_ses_pk3" &lt;code&gt;infinispan&lt;/code&gt;</li>
<li>#39454 JGroups errors when running a containerized Keycloak in Strict FIPS mode and with Istio &lt;code&gt;infinispan&lt;/code&gt;</li>
<li>#39500 Update Job Pod is listed in the keycloak discovery service &lt;code&gt;operator&lt;/code&gt;</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/106820</link><guid isPermaLink="true">https://forum.cloudron.io/post/106820</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Fri, 09 May 2025 07:21:03 GMT</pubDate></item></channel></rss>