Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Keycloak
  3. Keycloak - Package Updates

Keycloak - Package Updates

Scheduled Pinned Locked Moved Keycloak
25 Posts 1 Posters 2.9k Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Package UpdatesP Offline
    Package UpdatesP Offline
    Package Updates
    App Dev
    wrote on last edited by
    #16

    [1.2.4]

    • Update keycloak to 26.2.4
    • Full Changelog
    • #35278 Double click on social provider link causes page has expired error <code>login/ui</code>
    • #39021 After migrating to newer Keycloak, token refreshes using inherited offline sessions return access tokens with invalid exp value <code>oidc</code>
    • #39023 Keycloak 26.2.0 UI Performance Degradation <code>admin/ui</code>
    • #39173 duplicate key value violates unique constraint "constraint_offl_cl_ses_pk3" <code>infinispan</code>
    • #39454 JGroups errors when running a containerized Keycloak in Strict FIPS mode and with Istio <code>infinispan</code>
    • #39500 Update Job Pod is listed in the keycloak discovery service <code>operator</code>
    1 Reply Last reply
    0
    • Package UpdatesP Offline
      Package UpdatesP Offline
      Package Updates
      App Dev
      wrote on last edited by
      #17

      [1.2.5]

      • Update keycloak to 26.2.5
      • Full Changelog
      • Fix Securing Apps links to adapters docs
      • Email server credentials can be harvested through host/port manipulation admin/api
      • Fix doc link to FGAP v1 docs
      • Apply edits to Operators Guide docs
      • Edit Observability Guide docs
      • Fix callouts in Operator guide docs
      • Sessions from Infinispan should be mapped lazily for the Admin UI
      • Speed up Infinispan list of all sessions be more eagerly remove old client sessions
      • When logging in, all client sessions are loaded which is slow oidc
      • Authorization Code Flow Fails Scope Validation After Credential Definition Migration to Realm Level oid4vc
      1 Reply Last reply
      0
      • Package UpdatesP Offline
        Package UpdatesP Offline
        Package Updates
        App Dev
        wrote on last edited by
        #18

        [1.3.0]

        • Update keycloak to 26.3.0
        • Full Changelog
        • Account recovery with 2FA recovery codes, protecting users from lockout.
        • Simplified experiences for application developers with streamlined WebAuthn/Passkey registration and simplified account linking to identity providers via application initiated actions.
        • Broader connectivity with the ability to broker with any OAuth 2.0 compliant authorization server, and enhanced trusted email verification for OpenID Connect providers.
        • Asynchronous logging for higher throughput and lower latency, ensuring more efficient deployments.
        • For administrators, experimental rolling updates for patch releases mean minimized downtime and smoother upgrades.
        • The custom protocol, which was previously used for client-initiated account linking, is now deprecated.
        • #21995 Configurable probes in the Operator operator
        • #29116 Add supported config options for additional datasources dist/quarkus
        • #29596 Passkeys conditional UI: integration with username/password form authentication/webauthn
        • #38465 Name for OTP device should be unique account/api
        • #38985 Possibility to log details and representation to the jboss-logging listener
        1 Reply Last reply
        0
        • Package UpdatesP Offline
          Package UpdatesP Offline
          Package Updates
          App Dev
          wrote on last edited by
          #19

          [1.3.1]

          • Update keycloak to 26.3.1
          • Full Changelog
          1 Reply Last reply
          0
          • Package UpdatesP Offline
            Package UpdatesP Offline
            Package Updates
            App Dev
            wrote on last edited by
            #20

            [1.3.2]

            • Update keycloak to 26.3.2
            • Full Changelog
            • #40237 Add option "Requires short state parameter" to OIDC IDP authentication
            • #40970 Run clustering compatibility tests on release/x.y branches
            • #41034 Improve logging for client sessions load
            • #41257 Upgrade to Infinispan 15.0.18.Final infinispan
            • #39634 Update MariaDB connector to 3.5.3 dist/quarkus
            • #40553 Upgrade org.postgresql:postgresql to version 42.7.7 to address CVE-2025-49146 dependencies
            • #40736 CVE-2025-49574 - Exposure of Resource to Wrong Sphere vulnerability in io.vertx:vertx-core dependencies
            • #40784 Default jdbc-ping cluster setup for distributed caches fails in Oracle infinispan
            • #40980 Can't update security-admin-console via admin UI with volatile sessions infinispan
            • #40995 LDAP / ModelException: At least one condition should be provided to OR query core
            1 Reply Last reply
            0
            • Package UpdatesP Offline
              Package UpdatesP Offline
              Package Updates
              App Dev
              wrote on last edited by
              #21

              [1.3.3]

              • Update keycloak to 26.3.3
              • Full Changelog
              • #​39562 Breaking template change: Unknown locale input field added to user-profile registration page <code>user-profile</code>
              • #​40984 Backchannel logout token with an unexpected signature algorithm key <code>oidc</code>
              • #​41023 Can't send e-mails to international e-mail addresses: bad UTF-8 syntax <code>core</code>
              • #​41098 Locked out after upgrade to 26.3.1 due to missing sub in lightweight access token <code>core</code>
              • #​41268 --optimized flag and providers jar are incompatible when used with tools changing last-modify-date <code>dist/quarkus</code>
              • #​41290 Concurrent starts with JDBC_PING lead to a split cluster <code>infinispan</code>
              • #​41390 JDBC_PING2 doesn't merge split clusters after a while <code>infinispan</code>
              • #​41421 Broken link securing-cache-communication in caching docs <code>docs</code>
              • #​41423 Duplicate IDs in generated all configuration docs <code>docs</code>
              • #​41469 Uncaught exception cases unclosed spans in tracing <code>dist/quarkus</code>
              1 Reply Last reply
              0
              • Package UpdatesP Offline
                Package UpdatesP Offline
                Package Updates
                App Dev
                wrote on last edited by
                #22

                [1.3.4]

                • Update keycloak to 26.3.4
                • Full Changelog
                • #​40630 Double check when working with multithreading. SAST
                • #​42245 Upgrade to Quarkus 3.20.2.2
                • #​35825 Per client session idle time capped by realm level client idle timeout core
                • #​40374 Random but frequent duplicate key value violates unique constraint "constraint_offl_us_ses_pk2" errors authentication
                • #​40463 Login to Account Console produces two consecutive LOGIN events account/ui
                • #​40857 Unbounded login_hint Parameter Can Corrupt KC_RESTART Cookie and Break Login Flow oidc
                • #​41427 Parallel token exchange fails if client session is expired token-exchange
                • #​41801 Lack of coordination in database creation in 26.3.0 causes deployment failures (Reopen) core
                • #​41942 Uncaught server error: org.keycloak.models.ModelException: Database operation failed : Sync LDAP Groups to Keycloak (Custom Provider) core
                • #​42012 Client session timestamp not updated in the database if running multiple nodes infinispan
                1 Reply Last reply
                0
                • Package UpdatesP Offline
                  Package UpdatesP Offline
                  Package Updates
                  App Dev
                  wrote last edited by
                  #23

                  [1.3.5]

                  • Update keycloak to 26.3.5
                  • Full Changelog
                  1 Reply Last reply
                  0
                  • Package UpdatesP Offline
                    Package UpdatesP Offline
                    Package Updates
                    App Dev
                    wrote last edited by
                    #24

                    [1.4.0]

                    • Update keycloak to 26.4.0
                    • Full Changelog
                    • Passkeys for seamless, passwordless authentication of users.
                    • Federated Client Authentication to use SPIFFE or Kubernetes service account tokens for client authentication.
                    • Simplified deployments across multiple availability zones to boost availability.
                    • FAPI 2 Final: Keycloak now supports the final specifications of FAPI 2.0 Security Profile and FAPI 2.0 Message Signing.
                    • DPoP: The OAuth 2.0 Demonstrating Proof-of-Possession at the Application Layer (DPoP) is now fully supported. Improvements include the ability to bind only refresh tokens for public clients, and securing all Keycloak endpoints with DPoP tokens.
                    • FIPS 140-2 mode now supports EdDSA
                    • Listing supported OAuth standards on one page
                    • Automatic certificate management for SAML clients
                    • Update Email Workflow (supported)
                    • Optional email domain for organizations
                    1 Reply Last reply
                    0
                    • Package UpdatesP Offline
                      Package UpdatesP Offline
                      Package Updates
                      App Dev
                      wrote last edited by
                      #25

                      [1.4.1]

                      • Update keycloak to 26.4.1
                      • Full Changelog
                      • #​43020 Secure Client-Initiated Renegotiation - disable by default dist/quarkus
                      • #​42990 Hide read-only email attribute in update profile context with update email enabled user-profile
                      • #​43357 JDBC_PING should publish its physical address on startup
                      • #​40965 Group permission denies to view user admin/fine-grained-permissions
                      • #​41292 openid-connect flow is missing response type on language change authentication
                      • #​42565 Standard Token Exchange: chain of exchanges eventually fails token-exchange
                      • #​42676 Security Defenses realm settings lost when switching between Headers and Brute Force Detection tabs (v25+) admin/ui
                      • #​42907 Race condition in authorization service leads to NullPointerException when evaluating permissions during concurrent resource deletion authorization-services
                      • #​43042 Avoid NPE in FederatedJWTClientAuthenticator when checking for supported assertion types core
                      • #​43070 Update email page with pending verification email messages prefilled with old email user-profile
                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search