Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #50785 CVE-2026-35563: LDAP client implementation in version 2.1.7 does not verify if the server certificate matches th
Keycloak 25 to 26
Every Keycloak 26.x release the archive holds, 50 of them, starting at 26.0.0 and running to 26.7.3. The publisher writes these one at a time and its documentation describes the version you are on, so the run between two majors is not laid out anywhere as a list.
- Releases
- 5050 carry notes
- Opened
- 4 Oct 20241.9 years ago
- Span
- 23 monthsto 31 Aug 2026
- Breaking
- 1tagged by the publisher
- Advisories closed
- 24security
The turn
Tagged breaking
1 of these releases carries the breaking label: 26.3.3. The label is matched from words in the publisher’s own notes, so a release that changed an API without using the word does not carry it.
Every 26.x release
All Keycloak releasesUpgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #49570 CVE-2026-45292 OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation dependencies #5
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #49429 [CVE-2026-9793] JWE request object bypasses requestObjectSignatureAlg enforcement oidc #50445 [CVE-2026-4629] Pr
Highlights This release features new capabilities for users and administrators of Keycloak. The highlights of this release are: Automate user provisioning with the SCIM API (preview) Simplified multi-cluster high availability without extern
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #50344 CVE-2026-9099 Keycloak: group-admin escalation to realm-admin #50345 CVE-2026-9083 Keycloak: keycloak: informati
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #47707 CVE-2026-4800 lodash vulnerable to Code Injection via `_.template` imports key names account/ui #47935 [CVE-2026
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #47485 CVE-2026-33871 HTTP/2 CONTINUATION Frame Flood Denial of Service #47486 CVE-2026-33870 RFC violation: HTTP Reque
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #47276 CVE-2026-4366 Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling core #47619 CVE-2026-4633 Keyc
Highlights This release features new capabilities for users and administrators of Keycloak. The highlights of this release are: JWT Authorization Grant, enabling external-to-internal token exchange using externally signed JWT assertions. Fe
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #45493 CVE-2025-14083 keycloak-server: Keycloak: Improper Access Control in Admin REST API leads to information disclos
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #45645 CVE-2026-1180 - Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_u
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #46909 CVE-2026-3047 SAML broker: Authentication bypass due to disabled SAML client completing IdP-initiated login #469
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #45646 CVE-2026-1190 - Keycloak SAML brokering: Response delay due to unchecked NotOnOrAfter in SubjectConfirmationData
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #46144 CVE-2026-1609 Disabled users can still obtain tokens via JWT Authorization Grant #46145 CVE-2026-1529 Forged inv
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesSecurity fixes #44994 CVE-2025-67735 - netty-codec-http: Request Smuggling via CRLF Injection dependencies Enhancements #43443 Keycloa
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #44863 x-robots HTTP header missing for static Keycloak resources, and REST endpoint responses #45009 Performance improve
Highlights This release features new capabilities for users and administrators of Keycloak. The highlights of this release are: Workflows to automate administrative tasks and process within a realm. JWT Authorization Grants, our recommended
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #43156 [Docs] Warn users about printing headers in HTTP access logs docs #43643 Upgrade to Quarkus 3.27.1 dist/quarkus Bu
Highlights This release adds filtering of LDAP referrals by default. This change enhances security and aligns with best practices for LDAP configurations. If you can not upgrade to this release yet, we recommend disabling LDAP referrals in
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesBugs #42601 Flaky test: org.keycloak.testsuite.broker.KcOidcBrokerTest#testPostBrokerLoginFlowWithOTP ci #43212 Document missing artif
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #10388 Allow to hide client scopes from scopes_supported in discovery endpoint #43076 Add rate limiter for sending verifi
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #42991 Final review and update for UPDATE_EMAIL documentation docs #43351 Make pending email verification attribute remov
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesNew features #43020 Secure Client-Initiated Renegotiation - disable by default dist/quarkus Enhancements #42990 Hide read-only email a
Highlights This release features new capabilities focused on security enhancements, deeper integration, and improved server administration. The highlights of this release are: Passkeys for seamless, passwordless authentication of users. Fed
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #41371 Upgrade to Quarkus 3.20.3 LTS dist/quarkus #41373 Remove explicit MariaDB connector dependency dist/quarkus Bugs #
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #40630 Double check when working with multithreading. SAST #42245 Upgrade to Quarkus 3.20.2.2 Bugs #35825 Per client sess
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #41558 Ensure cache configuration has correct number of owners #41934 Infinispan 15.0.19.Final #41963 Upgrade to Quarkus
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesNew features #40237 Add option "Requires short state parameter" to OIDC IDP authentication Enhancements #40970 Run clustering compatib
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #40851 Upgrade to Infinispan 15.0.16.Final #40962 Update limitations of the preview feature rolling updates for patch rel
Highlights This release delivers advancements to optimize your system and improve the experience of users, developers and administrators: Account recovery with 2FA recovery codes, protecting users from lockout. Simplified experiences for ap
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #39469 Fix Securing Apps links to adapters docs #39486 Email server credentials can be harvested through host/port manipu
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #39418 Clarify when to use podman docs Bugs #35278 Double click on social provider link causes page has expired error log
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesNew features #38985 Possibility to log details and representation to the jboss-logging listener Enhancements #39080 Standardize introd
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #39142 Make distribution startup timeout configurable testsuite Bugs #39125 [Keycloak CI] - FIPS UT - Run crypto tests ci
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #38956 Clarify upgrade instructions #39057 Change the title for Grafana dashboards guide to plural docs #39059 Document o
Highlights Supported Standard Token Exchange In this release, we added support for the Standard token exchange! The token exchange feature was in preview for a long time, so we are glad to finally support the standard token exchange. For no
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #38409 Upgrade to Quarkus 3.15.4 dist/quarkus #38764 OTel: Unable to disable sampling at runtime; tracing-sampler-ratio v
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #37433 Allow admin to disable automatic refresh of event views admin/ui #37711 Upgrade to Infinispan 15.0.14 Bugs #37320
Highlights Send Reset Email force login again for federated users after reset credentials In version 26.1.1 a new configuration option was added to the reset-credential-email (Send Reset Email) authenticator to allow changing the default be
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesDeprecated features #525 Drop support for end-of-life versions of Node.js Enhancements #573 Convert tests to standard modules to upgra
Highlights New option in X.509 authenticator to abort authentication if CRL is outdated The X.509 authenticator has a new option x509-cert-auth-crl-abort-if-non-updated (CRL abort if non updated in the Admin Console) to abort the login if a
Highlights Transport stack jdbc-ping as new default Keycloak now uses by default its database to discover other nodes of the same cluster, which removes the need of additional network related configurations especially for cloud providers. I
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #33569 Show User Events on dedicated tab on Client-/User-Details #34091 Username Form should support autocomplete login/u
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #34882 Edits to Authorization Services guide #34916 Addresse QE comments on Server Administration guide #34931 Upgrade to
Highlights Admin events might include now additional details about the context when the event is fired In this release, admin events might hold additional details about the context when the event is fired. When upgrading you should expect t
Highlights LDAP users are created as enabled by default when using Microsoft Active Directory If you are using Microsoft AD and creating users through the administrative interfaces, the user will created as enabled by default. In previous v
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #34284 Keycloak-admin-client should work with the future versions of Keycloak server admin/client-java #34382 Make the or
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #32110 [Documentation] - Configuring trusted certificates - Fully specify truststore path dist/quarkus Bugs #15635 oidc -
Upgrading Before upgrading refer to the migration guide for a complete list of changes.All resolved issuesEnhancements #32152 Clarify the behaviour of multiple Operator versions installed in the same cluster operator #33275 Better logging w
Highlights Organizations supported Starting with Keycloak 26, the Organizations feature is fully supported. Client libraries updates Dedicated release cycle for the client libraries From this release, some of the Keycloak client libraries w