Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESKEYCLOAKVERIFIED

PUBLISHER UPDATE · KEYCLOAK-26.7.4

KEYCLOAK-26.7.4 release notes and known issues

26.7.4

Scope: Keycloak. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #52834 [CVE-2026-90997] Default MySQL/MariaDB row counts make stateless replay gates accept reused artifacts #52835 [ CVE-2026-79651 ] Keycloak Unauthenticated Denial of Service via Unbounded Locale Caching #52836 [ CVE-2026-74909 ] Incomplete fix: percent-encoded semicolon bypasses matrix parameter stripping in PathMatcher #52837 [ CVE-2026-19607 ] Username Takeover Leading to Account Lockout #52838 [ CVE-2026-17526 ] Privilege escalation: the "impersonation" role can impersonate a realm administrator #52839 [ CVE-2026-18212 ] SAML Redirect DEFLATE helpers leak native zlib state Enhancements #52354 Upgrade to Quarkus 3.33.3.2 dist/quarkus Bugs #49635 Performance issue with 26.6.2 dist/quarkus #51102 Flaky test: org.keycloak.testsuite.oauth.AccessTokenTest#accessTokenRequest ci #52015 New links errors for https://quarkus.io/guides docs #52172 Cached `RealmAdapter.isUserManagedAccessAllowed()` returns `isEnabled()` infinispan #52173 `realm_client` is computed into a client's attributes and then persisted on save admin/api #52233 Oracle 19 full client OCI driver crashes on startup since 26.6.0 — SQLFeatureNotSupportedException on setNetworkTimeout dist/quarkus #52241 Clicking on a sub group in the admin console throws an exception admin/ui #52283 Flaky test SessionRestServiceTest.testGetDevicesSessions testsuite #52430 Flaky test: userprofile.spec.ts fails with timeout on "no-users-found-empty-action" in serial suite testsuite

Improvements and security content

  • Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #52834 [CVE-2026-90997] Default MySQL/MariaDB row counts make stateless replay gates accept reused artifacts #52835 [ CVE-2026-79651 ] Keycloak Unauthenticated Denial of Service via Unbounded Locale Caching #52836 [ CVE-2026-74909 ] Incomplete fix: percent-encoded semicolon bypasses matrix parameter stripping in PathMatcher #52837 [ CVE-2026-19607 ] Username Takeover Leading to Account Lockout #52838 [ CVE-2026-17526 ] Privilege escalation: the "impersonation" role can impersonate a realm administrator #52839 [ CVE-2026-18212 ] SAML Redirect DEFLATE helpers leak native zlib state Enhancements #52354 Upgrade to Quarkus 3.33.3.2 dist/quarkus Bugs #49635 Performance issue with 26.6.2 dist/quarkus #51102 Flaky test: org.keycloak.testsuite.oauth.AccessTokenTest#accessTokenRequest ci #52015 New links errors for https://quarkus.io/guides docs #52172 Cached `RealmAdapter.isUserManagedAccessAllowed()` returns `isEnabled()` infinispan #52173 `realm_client` is computed into a client's attributes and then persisted on save admin/api #52233 Oracle 19 full client OCI driver crashes on startup since 26.6.0 — SQLFeatureNotSupportedException on setNetworkTimeout dist/quarkus #52241 Clicking on a sub group in the admin console throws an exception admin/ui #52283 Flaky test SessionRestServiceTest.testGetDevicesSessions testsuite #52430 Flaky test: userprofile.spec.ts fails with timeout on "no-users-found-empty-action" in serial suite testsuite

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Keycloak

Affected versions

  • 26.7.4
  • 3.33.3.2
  • 26.6.2
  • 26.6.0

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence