You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<p>Before upgrading refer to <ahref="https://www.keycloak.org/docs/latest/upgrading/#migration-changes">the migration guide</a> for a complete list of changes.</p>
5
+
6
+
<h2>All resolved issues</h2>
7
+
8
+
<h3>Security fixes</h3>
9
+
<ul>
10
+
<li><ahref="https://github.com/keycloak/keycloak/issues/45645">#45645</a> CVE-2026-1180 - Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri <code>oidc</code></li>
<li><ahref="https://github.com/keycloak/keycloak/issues/45650">#45650</a> CVE-2025-14777 - Keycloak IDOR in realm client creating/deleting </li>
13
+
<li><ahref="https://github.com/keycloak/keycloak/issues/45653">#45653</a> CVE-2025-14082 keycloak-server: Keycloak Admin REST API: Improper Access Control leads to sensitive role metadata information disclosure </li>
14
+
<li><ahref="https://github.com/keycloak/keycloak/issues/46719">#46719</a> CVE-2026-3121 - Keycloak: Privilege escalation via manage-clients permission </li>
15
+
<li><ahref="https://github.com/keycloak/keycloak/issues/46723">#46723</a> CVE-2026-3190 - Information Disclosure via improper role enforcement in UMA 2.0 Protection API <code>core</code></li>
16
+
<li><ahref="https://github.com/keycloak/keycloak/issues/46922">#46922</a> CVE-2026-3911 Keycloak: Information disclosure of disabled user attributes via administrative endpoint <code>user-profile</code></li>
17
+
<li><ahref="https://github.com/keycloak/keycloak/issues/47062">#47062</a> CVE-2026-2366 Authorization Bypass: Unprivileged tokens can enumerate user organization memberships <code>organizations</code></li>
18
+
</ul>
19
+
20
+
21
+
22
+
23
+
24
+
<h3>Bugs</h3>
25
+
<ul>
26
+
<li><ahref="https://github.com/keycloak/keycloak/issues/45889">#45889</a> Federated user disabled when external DB unavailable, never re-enabled <code>storage</code></li>
<li><ahref="https://github.com/keycloak/keycloak/issues/46296">#46296</a> UsersResource.search briefRepresentation started to return user attributes <code>admin/api</code></li>
29
+
<li><ahref="https://github.com/keycloak/keycloak/issues/46379">#46379</a> Unexpected error when logging out with offline session and external IDP <code>oidc</code></li>
30
+
<li><ahref="https://github.com/keycloak/keycloak/issues/46459">#46459</a> Operator-built DB config: targetServerType=primary not applied / connection validation not working after master-replica failover (26.5.0) <code>operator</code></li>
31
+
<li><ahref="https://github.com/keycloak/keycloak/issues/46588">#46588</a> Partial LDAP sync duration does not follow the defined value in user federation <code>ldap</code></li>
32
+
<li><ahref="https://github.com/keycloak/keycloak/issues/46605">#46605</a> 26.5.4 startup regression with many realms: RealmCacheSession.prepareCachedRealm() scans master admin role composites per realm (O(N²)) <code>core</code></li>
33
+
<li><ahref="https://github.com/keycloak/keycloak/issues/46656">#46656</a> Em-Hyphens in SPI options on cache configuration page <code>docs</code></li>
34
+
<li><ahref="https://github.com/keycloak/keycloak/issues/46663">#46663</a> JGroups bind port configuration ignored when --cache-embedded-network-bind-port set <code>infinispan</code></li>
35
+
<li><ahref="https://github.com/keycloak/keycloak/issues/46669">#46669</a> SPIFFE Client assertion throws a NullPointerException if no client is found <code>token-exchange</code></li>
36
+
<li><ahref="https://github.com/keycloak/keycloak/issues/47079">#47079</a> Do not allow fetching organizations of a member if not a member of the current organization <code>organizations</code></li>
0 commit comments