Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Offical apps | Community apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Keycloak
  3. Keycloak - Package Updates

Keycloak - Package Updates

Scheduled Pinned Locked Moved Keycloak
47 Posts 1 Posters 15.5k Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Package UpdatesP
    Package UpdatesP
    Package Updates
    wrote on last edited by
    #41

    [1.6.2]

    • Update keycloak to 26.6.2
    • Full Changelog
    • #47485 CVE-2026-33871 HTTP/2 CONTINUATION Frame Flood Denial of Service
    • #47486 CVE-2026-33870 RFC violation: HTTP Request Smuggling primitive via Chunked Extension Quoted-String Parsing
    • #47932 [CVE-2026-4628] Improper Access Control on Keycloak Server through UMA resource management endpoints via PUT parameters authorization-services
    • #48049 [CVE-2026-37980] Stored XSS in select-organization.ftl - FreeMarker HTML-escape insufficient in inline JS handler organizations
    • #48329 JDBC_PING in 26.6 should not fail with 26.7 schema changes
    • #48348 Escape expressions in JS blocks in FTL pages
    • #38526 Duplicate user attribute values cannot be removed core
    • #47901 Realm import with --import-realm fails with ModelValidationException when Admin Permissions is enabled admin/fine-grained-permissions
    • #48040 User session limit generates fatal error authentication
    • #48185 Deleted workflow still attempting to run workflows
    1 Reply Last reply
    0
    • Package UpdatesP
      Package UpdatesP
      Package Updates
      wrote on last edited by
      #42

      [1.6.3]

      • Update keycloak to 26.6.3
      • Full Changelog
      • #47707 CVE-2026-4800 lodash vulnerable to Code Injection via _.template imports key names account/ui
      • #47935 [CVE-2026-4874] Server-Side Request Forgery via OIDC token endpoint manipulation oidc
      • #48036 [CVE-2026-37977] CORS Access-Control-Allow-Origin reflected from unverified JWT azp claim on UMA token endpoint authorization-services
      • #48709 [CVE-2026-7500] Improper Access Control on Keycloak Server when the account Account API feature is disabled account/api
      • #48695 Add startup check for missing database indexes
      • #45957 Handling of CORS requests in the Admin UI ineffective / open for CSRF admin/ui
      • #48430 Wildcard redirect URI matching does not enforce host boundary when * is placed directly after hostname oidc
      • #48438 Keycloak 26.6.0/26.6.1 exits (code 1) ~100ms after async realm migration completes; migrations not persisted core
      • #48584 Updating Keycloak to 26.6.x fails on SQL Server with case sensitive collation core
      • #48877 Keycloak 26.6.1 does not persist UPDATE_PASSWORD for LDAP/AD federated users after temporary password reset ldap
      1 Reply Last reply
      0
      • Package UpdatesP
        Package UpdatesP
        Package Updates
        wrote on last edited by
        #43

        [1.6.4]

        • Update keycloak to 26.6.4
        • Full Changelog
        • #50344 CVE-2026-9099 Keycloak: group-admin escalation to realm-admin
        • #50345 CVE-2026-9083 Keycloak: keycloak: information disclosure through arbitrary filesystem path probing
        • #50347 CVE-2026-9086 Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass
        • #50349 CVE-2026-9705 Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token
        • #50350 CVE-2026-9795 Keycloak: keycloak: privilege escalation via improper scope mapping enforcement
        • #50351 CVE-2026-9799 Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass
        • #50352 CVE-2026-9800 Keycloak: keycloak policy enforcer: authorization bypass via incorrect uri comparison
        • #50357 CVE-2026-11800 Keycloak: Authentication bypass via JWT algorithm confusion
        • #50100 Upgrade to Quarkus 3.33.2.1
        • #49700 Incorrect migration guide reference docs
        1 Reply Last reply
        0
        • Package UpdatesP
          Package UpdatesP
          Package Updates
          wrote on last edited by
          #44

          [1.7.0]

          • Update keycloak to 26.7.0
          • Full Changelog
          • #49427 [CVE-2026-9796] Admin role rename TOCTOU bypasses checkAdminRoles realm-wide escalation from manage-clients admin/rbac
          • #49430 [CVE-2026-9689] HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication oidc
          • #49432 [CVE-2026-9798] CIBA authentication flow bypasses brute-force account lockout oidc
          • #49766 [CVE-2026-11986] FGAP v1 allows unassigning any role admin/fine-grained-permissions
          • #44013 Deprecate the Twitter IDP implementation due to old twitter4j library identity-brokering
          • #48104 Remove support for token-exchange-external-internal:v2 token-exchange/federated
          • #49270 Remove the batching option for the persistent sessions
          • #46543 Step-up authentication for SAML - supported authentication
          • #35650 Compatibility profiles
          • #20128 Add support for reencrypt OpenShift Routes to the Operator operator
          1 Reply Last reply
          0
          • Package UpdatesP
            Package UpdatesP
            Package Updates
            wrote last edited by
            #45

            [1.7.1]

            • Update keycloak to 26.7.1
            • Full Changelog
            • [CVE-2026-9793] JWE request object bypasses requestObjectSignatureAlg enforcement oidc (#49429)
            • [CVE-2026-4629] Privilege escalation via hardcoded role mapper injection in manage-clients admin/api (#50445)
            • [CVE-2026-14209] Keycloak Admin UI Extension brute-force-user User Disclosure via search=id: under FGAP v2 admin/fine-grained-permissions (#50569)
            • [CVE-2026-14614] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass in Client Scope Assignment admin/fine-grained-permissions (#50615)
            • [CVE-2026-14615] FGAP v2 parent group children endpoint bypasses per-child view permission filter admin/fine-grained-permissions (#50617)
            • WebAuthn authenticator attachment policy is bypassed when the client omits the attachment field authentication/webauthn (#50719)
            • Kustomize cluster-wide faulty Role&RoleBinding operator (#50836)
            • New Password is commited when multiple Password Reset is detected authentication (#50850)
            • 500 when client requests organization scope with it already set to Default authentication (#50882)
            • IllegalFormatConversionException in LiquibaseDBLockProviderFactory and wrong time conversion core (#50928)
            1 Reply Last reply
            0
            • Package UpdatesP
              Package UpdatesP
              Package Updates
              wrote last edited by
              #46

              [1.7.2]

              • Update keycloak to 26.7.2
              • Full Changelog
              • #49570 CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation dependencies
              • #50616 [CVE-2026-14613] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass via Role Groups Endpoint admin/fine-grained-permissions
              • #50955 [CVE-2026-59888 and CVE-2026-59889] Upgrade jackson-databind to 2.21.5 to fix
              • #50966 [CVE-2026-15945] Group hierarchy search discloses hidden parent groups under FGAP v2 admin/fine-grained-permissions
              • #51145 [CVE-2026-17048] Keycloak Admin REST API Leaks Vault-Resolved Rotated Client Secrets oidc
              • #51832 CVE-2026-15571 Predictable account-linking hash enables account takeover via malicious oidc client
              • #51833 CVE-2026-18963 Unauthenticated account takeover via reset-credentials flow bypass
              • #51344 Upgrade to Quarkus 3.33.3.1
              • #50751 Password denylist: false fpp warning on startup with large pre-computed .bloom file authentication
              • #51323 Custom realm-level role named admin cannot be updated in non-master realms after Keycloak 26.7.0 admin/rbac
              1 Reply Last reply
              0
              • Package UpdatesP
                Package UpdatesP
                Package Updates
                wrote last edited by
                #47

                [1.7.3]

                • Update keycloak to 26.7.3
                • Full Changelog
                • #50785 CVE-2026-35563: LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname ldap
                • #50997 [CVE-2026-16093] Required signed-JWT assertion policy can be bypassed with unsigned assertion headers oidc
                • #51003 [CVE-2026-16089] Authorization codes can be retargeted to another client session oidc
                • #51745 [CVE-2026-19729] Incomplete fix for CVE-2026-9083 relative path traversal still enables filesystem probing in 26.6.4 core
                • #50825 Creating an organization without a domain leads to an error organizations
                • #50963 V1 token-exchange strips the DPoP sender-constraint from a bound access token token-exchange
                • #51510 SQLGrammarException: The incoming request has too many parameters core
                • #51523 Sustained high CPU on all nodes after upgrade admin/api
                • #51554 Admin API per-request cost grows super-linearly with realm count since 26.7.1 admin/api
                • #51589 NPE in RoleUtils.expandCompositeRoles when a cached client scope references a deleted role core
                1 Reply Last reply
                0

                Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                With your input, this post could be even better 💗

                Register Login
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Don't have an account? Register

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • Bookmarks
                • Search