Skip to content

keycloak

Secrets & Credentials

Open source Identity and Access Management (IAM) platform that adds authentication and authorization to applications with minimal effort

Java Latest 26.6.2 · 15d ago Security brief →

Features

  • User federation across multiple identity stores
  • Strong authentication mechanisms (password, OTP, social login)
  • Comprehensive user management and role‑based access control

Recent releases

View all 11 releases →
Upgrade now
26.6.2 Breaking risk
Auth RBAC Crypto / TLS +1 more

CVE fixes

26.6.1 Breaking risk
Breaking changes
  • MigrateTo26_6_0 modifies custom browser flows, breaking existing realm authentication
Security fixes
  • CVE-2026-4366: Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling
  • CVE-2026-4633: Keycloak user enumeration via identity-first login
Notable features
  • Database data at rest encryption
  • CloudNativePG updated to 1.29
26.6.0

Based on the provided changelog, here is a summary of the key changes, categorized by their impact: ### 🚀 Key Improvements & Features * **New Capabilities:** Added support for-related features such as managing credentials/secrets via LDAP and potential new automation for developers. * **Performance & Efficiency:** * Significant optimizations for resource management, including smarter handling of JDBC connections and reduced thread consumption. * Improved database connection mana

26.5.7 Security relevant
Security fixes
  • CVE-2025-14083 Improper Access Control in Admin REST API leads to information disclosure
  • CVE-2026-1002 Static handler component cache manipulation enables denial of static file access
  • CVE-2026-3429 Improper Access Control for Level of Assurance during credential deletion
26.5.6 Security relevant
Security fixes
  • CVE-2026-1180 - Blind SSRF in OIDC Dynamic Client Registration via jwks_uri
  • CVE-2026-1035 - Refresh Token Reuse Bypass via TOCTOU Race Condition
  • CVE-2025-14777 - IDOR in realm client creating/deleting

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
34,724
Forks
8,429
Languages
Java TypeScript FreeMarker

Install & Platforms

Install via
docker binary

Community & Support

Beta — feedback welcome: [email protected]