Skip to content
release
BETA
Releases
Tools
Vendors
Trending
$refs.securityHub.focus())"
:aria-expanded="open"
aria-haspopup="menu"
class="inline-flex items-center gap-1 px-3 py-1.5 rounded text-[13px] font-medium transition-colors text-[var(--text-secondary)] dark:text-[var(--text-muted)] hover:text-[var(--text-primary)] dark:hover:text-[var(--text-primary)] hover:bg-[var(--surface-hover)] dark:hover:bg-[var(--surface-elevated)]"
>
Security
Tools
/
keycloak
KE
keycloak
Secrets & Credentials
Open source Identity and Access Management (IAM) platform that adds authentication and authorization to applications with minimal effort
Java
·
Latest 26.6.2 · 15d ago
Security brief →
Features
User federation across multiple identity stores
Strong authentication mechanisms (password, OTP, social login)
Comprehensive user management and role‑based access control
Upgrade now
26.6.2
Breaking risk
·
15d
Auth
RBAC
Crypto / TLS
+1 more
CVE fixes
26.6.1
Breaking risk
·
1mo
Breaking changes
MigrateTo26_6_0 modifies custom browser flows, breaking existing realm authentication
Security fixes
CVE-2026-4366: Blind Server-Side Request Forgery (SSRF) via HTTP Redirect Handling CVE-2026-4633: Keycloak user enumeration via identity-first login
Notable features
Database data at rest encryption CloudNativePG updated to 1.29
26.6.0
·
1mo
Based on the provided changelog, here is a summary of the key changes, categorized by their impact:
### 🚀 Key Improvements & Features
* **New Capabilities:** Added support for-related features such as managing credentials/secrets via LDAP and potential new automation for developers.
* **Performance & Efficiency:**
* Significant optimizations for resource management, including smarter handling of JDBC connections and reduced thread consumption.
* Improved database connection mana
26.5.7
Security relevant
·
2mo
Security fixes
CVE-2025-14083 Improper Access Control in Admin REST API leads to information disclosure CVE-2026-1002 Static handler component cache manipulation enables denial of static file access CVE-2026-3429 Improper Access Control for Level of Assurance during credential deletion
26.5.6
Security relevant
·
2mo
Security fixes
CVE-2026-1180 - Blind SSRF in OIDC Dynamic Client Registration via jwks_uri CVE-2026-1035 - Refresh Token Reuse Bypass via TOCTOU Race Condition CVE-2025-14777 - IDOR in realm client creating/deleting
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Releases per month
Releases per month, last 12 months.
Cadence
0.4 / wk
Last release
15d
Tracked
11
Security score
7.0/10
OpenSSF
9.4/10
Open CVEs
0
Active maintainer
Community
GitHub stars
34,724
Forks
8,429
Contributors 90d
49
Open issues
2,826
Open PRs
400
Stars/wk velocity
0.0
HN peak
455
About
Languages
Java
·
TypeScript
·
FreeMarker
View on GitHub
Homepage
Documentation
{ copied = true; setTimeout(() => copied = false, 2000) })"
class="flex items-center gap-1.5 text-[12px] text-[var(--text-muted)] dark:text-[var(--text-muted)] hover:text-[var(--accent)] dark:hover:text-[var(--accent)] transition-colors"
>
Install & Platforms
Install via
docker
binary
About
Languages
Java
·
TypeScript
·
FreeMarker
View on GitHub
Homepage
Documentation
{ copied = true; setTimeout(() => copied = false, 2000) })"
class="flex items-center gap-1.5 text-[12px] text-[var(--text-muted)] dark:text-[var(--text-muted)] hover:text-[var(--accent)] dark:hover:text-[var(--accent)] transition-colors"
>
Install & Platforms
Install via
docker
binary
© 2026 releaseport. All rights reserved.
Feed
Tools
Feeds
Security
Brief
Search tools, categories, lists, and users
Use ↑↓ to navigate, Enter to open, Esc to close
No results for " "
⌘K to open
↑↓ navigate
⏎ open