Catalog / Identity

Keycloak changelog

Identity and access server that handles sign in on behalf of other applications, speaking OpenID Connect, OAuth 2.0 and SAML.

Latest
26.7.3
Shipped
31 Aug 2026yesterday
Collected
60 releasesback to 24 Mar 2024
Source
keycloak/keycloak
Project
keycloak.org
Advisories
82 publishednewest 2026
Feed
RSS

Every release of a major line in one list, which is the one view the publisher never writes: 24 to 25, 25 to 26. Only the lines whose first release the archive holds are listed, because a partial major would read as the whole of one.

Read today, the first day on record. Collection status

Version history

26.x50 releases
26.7.3

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #50785 CVE-2026-35563: LDAP client implementation in version 2.1.7 does not verify if the server certificate matches th

securityfixedchanged
26.7.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #49570 CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation dependencies #5

securityfixed
26.7.1

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #49429 [CVE-2026-9793] JWE request object bypasses requestObjectSignatureAlg enforcement oidc #50445 [CVE-2026-4629] Pr

securityaddedfixed
26.7.0

Highlights This release features new capabilities for users and administrators of Keycloak. The highlights of this release are: Automate user provisioning with the SCIM API (preview) Simplified multi-cluster high availability without extern

securityaddedfixed
26.6.4

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #50344 CVE-2026-9099 Keycloak: group-admin escalation to realm-admin #50345 CVE-2026-9083 Keycloak: keycloak: informati

securityfixed
26.6.3

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #47707 CVE-2026-4800 lodash vulnerable to Code Injection via `_.template` imports key names account/ui #47935 [CVE-2026

securityaddedfixed
26.6.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #47485 CVE-2026-33871 HTTP/2 CONTINUATION Frame Flood Denial of Service #47486 CVE-2026-33870 RFC violation: HTTP Reque

securityaddedfixed
26.6.1

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #47276 CVE-2026-4366 Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling core #47619 CVE-2026-4633 Keyc

securityfixedchanged
26.6.0

Highlights This release features new capabilities for users and administrators of Keycloak. The highlights of this release are: JWT Authorization Grant, enabling external-to-internal token exchange using externally signed JWT assertions. Fe

securityaddedfixed
26.5.7

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #45493 CVE-2025-14083 keycloak-server: Keycloak: Improper Access Control in Admin REST API leads to information disclos

securityfixed
26.5.6

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #45645 CVE-2026-1180 - Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_u

securityfixed
26.5.5

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #46909 CVE-2026-3047 SAML broker: Authentication bypass due to disabled SAML client completing IdP-initiated login #469

securityfixed
26.5.4

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #45646 CVE-2026-1190 - Keycloak SAML brokering: Response delay due to unchecked NotOnOrAfter in SubjectConfirmationData

securityaddedfixed
26.5.3

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #46144 CVE-2026-1609 Disabled users can still obtain tokens via JWT Authorization Grant #46145 CVE-2026-1529 Forged inv

securityfixedchanged
26.5.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #44994 CVE-2025-67735 - netty-codec-http: Request Smuggling via CRLF Injection dependencies Enhancements #43443 Keycloa

securityfixed
26.5.1

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #44863 x-robots HTTP header missing for static Keycloak resources, and REST endpoint responses #45009 Performance improve

security
26.5.0

Highlights This release features new capabilities for users and administrators of Keycloak. The highlights of this release are: Workflows to automate administrative tasks and process within a realm. JWT Authorization Grants, our recommended

securityaddedfixed
26.4.7

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #43156 [Docs] Warn users about printing headers in HTTP access logs docs #43643 Upgrade to Quarkus 3.27.1 dist/quarkus Bu

26.4.6

Highlights This release adds filtering of LDAP referrals by default. This change enhances security and aligns with best practices for LDAP configurations. If you can not upgrade to this release yet, we recommend disabling LDAP referrals in

securityaddedfixed
26.4.5

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesBugs #42601 Flaky test: org.keycloak.testsuite.broker.KcOidcBrokerTest#testPostBrokerLoginFlowWithOTP ci #43212 Document missing artif

26.4.4

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #10388 Allow to hide client scopes from scopes_supported in discovery endpoint #43076 Add rate limiter for sending verifi

addedchangedremoved
26.4.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #42991 Final review and update for UPDATE_EMAIL documentation docs #43351 Make pending email verification attribute remov

addedchanged
26.4.1

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesNew features #43020 Secure Client-Initiated Renegotiation - disable by default dist/quarkus Enhancements #42990 Hide read-only email a

securitychanged
26.4.0

Highlights This release features new capabilities focused on security enhancements, deeper integration, and improved server administration. The highlights of this release are: Passkeys for seamless, passwordless authentication of users. Fed

securityaddedfixed
26.3.5

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #41371 Upgrade to Quarkus 3.20.3 LTS dist/quarkus #41373 Remove explicit MariaDB connector dependency dist/quarkus Bugs #

securitychanged
26.3.4

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #40630 Double check when working with multithreading. SAST #42245 Upgrade to Quarkus 3.20.2.2 Bugs #35825 Per client sess

added
26.3.3

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #41558 Ensure cache configuration has correct number of owners #41934 Infinispan 15.0.19.Final #41963 Upgrade to Quarkus

breakingsecurity
26.3.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesNew features #40237 Add option "Requires short state parameter" to OIDC IDP authentication Enhancements #40970 Run clustering compatib

securityaddedchanged
26.3.1

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #40851 Upgrade to Infinispan 15.0.16.Final #40962 Update limitations of the preview feature rolling updates for patch rel

fixedchanged
26.3.0

Highlights This release delivers advancements to optimize your system and improve the experience of users, developers and administrators: Account recovery with 2FA recovery codes, protecting users from lockout. Simplified experiences for ap

securityaddedfixed
26.2.5

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #39469 Fix Securing Apps links to adapters docs #39486 Email server credentials can be harvested through host/port manipu

changedremoved
26.2.4

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #39418 Clarify when to use podman docs Bugs #35278 Double click on social provider link causes page has expired error log

changed
26.2.3

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesNew features #38985 Possibility to log details and representation to the jboss-logging listener Enhancements #39080 Standardize introd

addedchanged
26.2.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #39142 Make distribution startup timeout configurable testsuite Bugs #39125 [Keycloak CI] - FIPS UT - Run crypto tests ci

security
26.2.1

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #38956 Clarify upgrade instructions #39057 Change the title for Grafana dashboards guide to plural docs #39059 Document o

changed
26.2.0

Highlights Supported Standard Token Exchange In this release, we added support for the Standard token exchange! The token exchange feature was in preview for a long time, so we are glad to finally support the standard token exchange. For no

securityaddedchanged
26.1.5

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #38409 Upgrade to Quarkus 3.15.4 dist/quarkus #38764 OTel: Unable to disable sampling at runtime; tracing-sampler-ratio v

26.1.4

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #37433 Allow admin to disable automatic refresh of event views admin/ui #37711 Upgrade to Infinispan 15.0.14 Bugs #37320

26.1.3

Highlights Send Reset Email force login again for federated users after reset credentials In version 26.1.1 a new configuration option was added to the reset-credential-email (Send Reset Email) authenticator to allow changing the default be

securityaddedfixed
26.1.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesDeprecated features #525 Drop support for end-of-life versions of Node.js Enhancements #573 Convert tests to standard modules to upgra

26.1.1

Highlights New option in X.509 authenticator to abort authentication if CRL is outdated The X.509 authenticator has a new option x509-cert-auth-crl-abort-if-non-updated (CRL abort if non updated in the Admin Console) to abort the login if a

addedchanged
26.1.0

Highlights Transport stack jdbc-ping as new default Keycloak now uses by default its database to discover other nodes of the same cluster, which removes the need of additional network related configurations especially for cloud providers. I

securityaddedchanged
26.0.8

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #33569 Show User Events on dedicated tab on Client-/User-Details #34091 Username Form should support autocomplete login/u

securityadded
26.0.7

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #34882 Edits to Authorization Services guide #34916 Addresse QE comments on Server Administration guide #34931 Upgrade to

securityaddedchanged
26.0.6

Highlights Admin events might include now additional details about the context when the event is fired In this release, admin events might hold additional details about the context when the event is fired. When upgrading you should expect t

securityaddedchanged
26.0.5

Highlights LDAP users are created as enabled by default when using Microsoft Active Directory If you are using Microsoft AD and creating users through the administrative interfaces, the user will created as enabled by default. In previous v

changed
26.0.4

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #34284 Keycloak-admin-client should work with the future versions of Keycloak server admin/client-java #34382 Make the or

securitychanged
26.0.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #32110 [Documentation] - Configuring trusted certificates - Fully specify truststore path dist/quarkus Bugs #15635 oidc -

security
26.0.1

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #32152 Clarify the behaviour of multiple Operator versions installed in the same cluster operator #33275 Better logging w

26.0.0

Highlights Organizations supported Starting with Keycloak 26, the Organizations feature is fully supported. Client libraries updates Dedicated release cycle for the client libraries From this release, some of the Keycloak client libraries w

securityaddedfixed
25.x6 releases
25.0.6

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesBugs #30604 Network response was not OK. saml #31165 Re-enabling a temporarily locked user (brute-force) deletes all user properties a

security
25.0.5

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesBugs #32084 SAML adapter IdMapperUpdaterSessionListener not executed when session ID changes adapter/saml #32754 CVE-2024-7341 Session

security
25.0.4

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #31963 Upgrade to Infinispan 15.0.7.Final Bugs #31299 NPM library of account-ui is unusable (@keycloak/keycloak-account-u

addedchanged
25.0.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #30094 Do not inherit 'https-client-auth' property for the management interface #30537 Document how Admin REST API endpoi

addedchanged
25.0.1

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #19750 Use a proper FreeMarker template for the new consoles account/ui #30346 Enhance masking around config-keystore dis

addedfixedchanged
25.0.0

Highlights Account Console v2 theme removed The Account Console v2 theme has been removed from Keycloak. This theme was deprecated in Keycloak 24 and replaced by the Account Console v3 theme. If you are still using this theme, you should mi

securityaddedfixed
24.x4 releases
24.0.5

Highlights Security issue with PAR clients using client_secret_post based authentication This release contains the fix of the important security issue affecting some OIDC confidential clients using PAR (Pushed authorization request). In cas

securitychanged
24.0.4

Highlights Partial update to user attributes when updating users through the Admin User API is no longer supported When updating user attributes through the Admin User API, you cannot execute partial updates when updating the user attribute

addedchanged
24.0.3

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #26695 Keycloak and MSAD: enabling account in MSAD does not propagate to Keycloak ldap Bugs #24201 Cannot disable LDAP-ba

changed
24.0.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #25057 Inconsistent behaviour on getting user permissions using authorization authorization-services #27433 Clarify forma

changed