Skip to content

keycloak

Secrets & Credentials

Open Source Identity and Access Management For Modern Applications and Services

Java Latest 26.7.0 · 18d ago Security brief →

Features

  • User federation and management
  • Strong authentication mechanisms
  • Fine‑grained authorization controls

Recent releases

View all 14 releases →
Review required
26.7.0 Breaking risk
Auth RBAC

Breaking changes — review before upgrading.

Upgrade now
26.6.4 Security relevant
Auth RBAC

group-admin escalation

Upgrade now
26.6.3 Breaking risk
Auth RBAC RCE / SSRF +2 more

lodash code injection fix

Upgrade now
26.6.2 Breaking risk
Auth RBAC Crypto / TLS +1 more

CVE fixes

26.6.1 Breaking risk
Breaking changes
  • MigrateTo26_6_0 modifies custom browser flows, breaking existing realm authentication
Security fixes
  • CVE-2026-4366: Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling
  • CVE-2026-4633: Keycloak user enumeration via identity-first login
Notable features
  • Database data at rest encryption
  • CloudNativePG updated to 1.29

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
35,724
Forks
8,639
Languages
Java TypeScript FreeMarker

Install & Platforms

Install via
binary docker

Community & Support

Beta — feedback welcome: [email protected]