Catalog / Keycloak

Keycloak 25 to 26

Every Keycloak 26.x release the archive holds, 50 of them, starting at 26.0.0 and running to 26.7.3. The publisher writes these one at a time and its documentation describes the version you are on, so the run between two majors is not laid out anywhere as a list.

Releases
5050 carry notes
Opened
4 Oct 20241.9 years ago
Span
23 monthsto 31 Aug 2026
Breaking
1tagged by the publisher
Advisories closed
24security

The turn

The last 25.x release the archive holds before the turn is 25.0.6, on 19 Sep 2024. 26.0.0 followed 15 days later. The archive holds no 25.x release after 26.0.0 opened.

Tagged breaking

1 of these releases carries the breaking label: 26.3.3. The label is matched from words in the publisher’s own notes, so a release that changed an API without using the word does not carry it.

Every 26.x release

All Keycloak releases
26.7.3securityfixedchanged

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #50785 CVE-2026-35563: LDAP client implementation in version 2.1.7 does not verify if the server certificate matches th

26.7.2securityfixed

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #49570 CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation dependencies #5

26.7.1securityaddedfixed

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #49429 [CVE-2026-9793] JWE request object bypasses requestObjectSignatureAlg enforcement oidc #50445 [CVE-2026-4629] Pr

26.7.0securityaddedfixed

Highlights This release features new capabilities for users and administrators of Keycloak. The highlights of this release are: Automate user provisioning with the SCIM API (preview) Simplified multi-cluster high availability without extern

26.6.4securityfixed

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #50344 CVE-2026-9099 Keycloak: group-admin escalation to realm-admin #50345 CVE-2026-9083 Keycloak: keycloak: informati

26.6.3securityaddedfixed

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #47707 CVE-2026-4800 lodash vulnerable to Code Injection via `_.template` imports key names account/ui #47935 [CVE-2026

26.6.2securityaddedfixed

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #47485 CVE-2026-33871 HTTP/2 CONTINUATION Frame Flood Denial of Service #47486 CVE-2026-33870 RFC violation: HTTP Reque

26.6.1securityfixedchanged

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #47276 CVE-2026-4366 Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling core #47619 CVE-2026-4633 Keyc

26.6.0securityaddedfixed

Highlights This release features new capabilities for users and administrators of Keycloak. The highlights of this release are: JWT Authorization Grant, enabling external-to-internal token exchange using externally signed JWT assertions. Fe

26.5.7securityfixed

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #45493 CVE-2025-14083 keycloak-server: Keycloak: Improper Access Control in Admin REST API leads to information disclos

26.5.6securityfixed

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #45645 CVE-2026-1180 - Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_u

26.5.5securityfixed

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #46909 CVE-2026-3047 SAML broker: Authentication bypass due to disabled SAML client completing IdP-initiated login #469

26.5.4securityaddedfixed

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #45646 CVE-2026-1190 - Keycloak SAML brokering: Response delay due to unchecked NotOnOrAfter in SubjectConfirmationData

26.5.3securityfixedchanged

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #46144 CVE-2026-1609 Disabled users can still obtain tokens via JWT Authorization Grant #46145 CVE-2026-1529 Forged inv

26.5.2securityfixed

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #44994 CVE-2025-67735 - netty-codec-http: Request Smuggling via CRLF Injection dependencies Enhancements #43443 Keycloa

26.5.1security

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #44863 x-robots HTTP header missing for static Keycloak resources, and REST endpoint responses #45009 Performance improve

26.5.0securityaddedfixed

Highlights This release features new capabilities for users and administrators of Keycloak. The highlights of this release are: Workflows to automate administrative tasks and process within a realm. JWT Authorization Grants, our recommended

26.4.7

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #43156 [Docs] Warn users about printing headers in HTTP access logs docs #43643 Upgrade to Quarkus 3.27.1 dist/quarkus Bu

26.4.6securityaddedfixed

Highlights This release adds filtering of LDAP referrals by default. This change enhances security and aligns with best practices for LDAP configurations. If you can not upgrade to this release yet, we recommend disabling LDAP referrals in

26.4.5

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesBugs #42601 Flaky test: org.keycloak.testsuite.broker.KcOidcBrokerTest#testPostBrokerLoginFlowWithOTP ci #43212 Document missing artif

26.4.4addedchangedremoved

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #10388 Allow to hide client scopes from scopes_supported in discovery endpoint #43076 Add rate limiter for sending verifi

26.4.2addedchanged

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #42991 Final review and update for UPDATE_EMAIL documentation docs #43351 Make pending email verification attribute remov

26.4.1securitychanged

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesNew features #43020 Secure Client-Initiated Renegotiation - disable by default dist/quarkus Enhancements #42990 Hide read-only email a

26.4.0securityaddedfixed

Highlights This release features new capabilities focused on security enhancements, deeper integration, and improved server administration. The highlights of this release are: Passkeys for seamless, passwordless authentication of users. Fed

26.3.5securitychanged

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #41371 Upgrade to Quarkus 3.20.3 LTS dist/quarkus #41373 Remove explicit MariaDB connector dependency dist/quarkus Bugs #

26.3.4added

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #40630 Double check when working with multithreading. SAST #42245 Upgrade to Quarkus 3.20.2.2 Bugs #35825 Per client sess

26.3.3breakingsecurity

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #41558 Ensure cache configuration has correct number of owners #41934 Infinispan 15.0.19.Final #41963 Upgrade to Quarkus

26.3.2securityaddedchanged

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesNew features #40237 Add option "Requires short state parameter" to OIDC IDP authentication Enhancements #40970 Run clustering compatib

26.3.1fixedchanged

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #40851 Upgrade to Infinispan 15.0.16.Final #40962 Update limitations of the preview feature rolling updates for patch rel

26.3.0securityaddedfixed

Highlights This release delivers advancements to optimize your system and improve the experience of users, developers and administrators: Account recovery with 2FA recovery codes, protecting users from lockout. Simplified experiences for ap

26.2.5changedremoved

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #39469 Fix Securing Apps links to adapters docs #39486 Email server credentials can be harvested through host/port manipu

26.2.4changed

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #39418 Clarify when to use podman docs Bugs #35278 Double click on social provider link causes page has expired error log

26.2.3addedchanged

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesNew features #38985 Possibility to log details and representation to the jboss-logging listener Enhancements #39080 Standardize introd

26.2.2security

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #39142 Make distribution startup timeout configurable testsuite Bugs #39125 [Keycloak CI] - FIPS UT - Run crypto tests ci

26.2.1changed

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #38956 Clarify upgrade instructions #39057 Change the title for Grafana dashboards guide to plural docs #39059 Document o

26.2.0securityaddedchanged

Highlights Supported Standard Token Exchange In this release, we added support for the Standard token exchange! The token exchange feature was in preview for a long time, so we are glad to finally support the standard token exchange. For no

26.1.5

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #38409 Upgrade to Quarkus 3.15.4 dist/quarkus #38764 OTel: Unable to disable sampling at runtime; tracing-sampler-ratio v

26.1.4

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #37433 Allow admin to disable automatic refresh of event views admin/ui #37711 Upgrade to Infinispan 15.0.14 Bugs #37320

26.1.3securityaddedfixed

Highlights Send Reset Email force login again for federated users after reset credentials In version 26.1.1 a new configuration option was added to the reset-credential-email (Send Reset Email) authenticator to allow changing the default be

26.1.2

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesDeprecated features #525 Drop support for end-of-life versions of Node.js Enhancements #573 Convert tests to standard modules to upgra

26.1.1addedchanged

Highlights New option in X.509 authenticator to abort authentication if CRL is outdated The X.509 authenticator has a new option x509-cert-auth-crl-abort-if-non-updated (CRL abort if non updated in the Admin Console) to abort the login if a

26.1.0securityaddedchanged

Highlights Transport stack jdbc-ping as new default Keycloak now uses by default its database to discover other nodes of the same cluster, which removes the need of additional network related configurations especially for cloud providers. I

26.0.8securityadded

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #33569 Show User Events on dedicated tab on Client-/User-Details #34091 Username Form should support autocomplete login/u

26.0.7securityaddedchanged

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #34882 Edits to Authorization Services guide #34916 Addresse QE comments on Server Administration guide #34931 Upgrade to

26.0.6securityaddedchanged

Highlights Admin events might include now additional details about the context when the event is fired In this release, admin events might hold additional details about the context when the event is fired. When upgrading you should expect t

26.0.5changed

Highlights LDAP users are created as enabled by default when using Microsoft Active Directory If you are using Microsoft AD and creating users through the administrative interfaces, the user will created as enabled by default. In previous v

26.0.4securitychanged

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #34284 Keycloak-admin-client should work with the future versions of Keycloak server admin/client-java #34382 Make the or

26.0.2security

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #32110 [Documentation] - Configuring trusted certificates - Fully specify truststore path dist/quarkus Bugs #15635 oidc -

26.0.1

Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #32152 Clarify the behaviour of multiple Operator versions installed in the same cluster operator #33275 Better logging w

26.0.0securityaddedfixed

Highlights Organizations supported Starting with Keycloak 26, the Organizations feature is fully supported. Client libraries updates Dedicated release cycle for the client libraries From this release, some of the Keycloak client libraries w