chore: upgrade to 26.6.4 #4

Closed
autonomic-bot wants to merge 0 commits from upgrade-26.6.4 into main

Recipe upgrade: keycloak/keycloak app image 26.6.3 → 26.6.4 (security patch).

Image tag changes

service image current new
app keycloak/keycloak 26.6.3 26.6.4
db mariadb 12.3 12.3 (up-to-date, no change)

Recipe version label is NOT bumped in this PR (left at 10.8.0+26.6.3); see the recommended release command below.

Upstream release notes

Upstream release notes: app keycloak/keycloak 26.6.3→26.6.4: https://github.com/keycloak/keycloak/releases/tag/26.6.4

26.6.4 (released 26 Jun 2026) is a security/bug-fix patch:

  • 8 CVEs fixed: group-admin escalation to realm-admin (CVE-2026-9099); information disclosure via arbitrary filesystem path probing (CVE-2026-9083); XSS via case-insensitive URI validation bypass (CVE-2026-9086); disabled-client takeover via registration access token (CVE-2026-9705); privilege escalation via improper scope mapping (CVE-2026-9795); UMA permission-ticket bypass (CVE-2026-9799); policy-enforcer authorization bypass via incorrect URI comparison (CVE-2026-9800); authentication bypass via JWT algorithm confusion (CVE-2026-11800).
  • Enhancement: upgrade to Quarkus 3.33.2.1.
  • Bug fixes only (build/docs/CI hygiene).
  • No breaking changes; refer to the Keycloak migration guide for the full list.

Operator action required

None — drop-in patch. Same KC_DB=mariadb backend, no compose/env/config changes, no migrations beyond the standard Keycloak upgrade procedure. Verified converging + serving (HTTP 200 on /realms/master) on a direct --chaos deploy on the cc-ci swarm (dev-keycloak.ci.commoninternet.net, since torn down).

After this PR merges, publish the new catalogue version with:

abra recipe release keycloak -z

(patch bump — 26.6.4 is a security/bug-fix patch with no breaking changes; -z bumps 10.8.0 → 10.8.1 and tags/publishes)

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

Recipe upgrade: keycloak/keycloak app image 26.6.3 → 26.6.4 (security patch). ## Image tag changes | service | image | current | new | |---------|--------------|---------|---------| | app | keycloak/keycloak | 26.6.3 | 26.6.4 | | db | mariadb | 12.3 | 12.3 (up-to-date, no change) | Recipe version label is NOT bumped in this PR (left at 10.8.0+26.6.3); see the recommended release command below. ## Upstream release notes **Upstream release notes:** app keycloak/keycloak 26.6.3→26.6.4: https://github.com/keycloak/keycloak/releases/tag/26.6.4 26.6.4 (released 26 Jun 2026) is a security/bug-fix patch: - 8 CVEs fixed: group-admin escalation to realm-admin (CVE-2026-9099); information disclosure via arbitrary filesystem path probing (CVE-2026-9083); XSS via case-insensitive URI validation bypass (CVE-2026-9086); disabled-client takeover via registration access token (CVE-2026-9705); privilege escalation via improper scope mapping (CVE-2026-9795); UMA permission-ticket bypass (CVE-2026-9799); policy-enforcer authorization bypass via incorrect URI comparison (CVE-2026-9800); authentication bypass via JWT algorithm confusion (CVE-2026-11800). - Enhancement: upgrade to Quarkus 3.33.2.1. - Bug fixes only (build/docs/CI hygiene). - No breaking changes; refer to the Keycloak migration guide for the full list. ## Operator action required None — drop-in patch. Same KC_DB=mariadb backend, no compose/env/config changes, no migrations beyond the standard Keycloak upgrade procedure. Verified converging + serving (HTTP 200 on /realms/master) on a direct --chaos deploy on the cc-ci swarm (dev-keycloak.ci.commoninternet.net, since torn down). ## Recommended release After this PR merges, publish the new catalogue version with: abra recipe release keycloak -z (patch bump — 26.6.4 is a security/bug-fix patch with no breaking changes; -z bumps 10.8.0 → 10.8.1 and tags/publishes) Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-07-03 04:12:03 +00:00
chore: upgrade to 26.6.4
All checks were successful
cc-ci/testme cc-ci: success
06338f2f03
autonomic-bot requested review from trav 2026-07-03 04:12:03 +00:00
autonomic-bot requested review from notplants 2026-07-03 04:12:03 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-cikeycloak @ 06338f2f passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `keycloak` @ `06338f2f` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/976/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/976) [![level](https://ci.commoninternet.net/runs/976/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/976) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/976) · [dashboard](https://ci.commoninternet.net/)
Author
Owner

Auto-closed by /recipe-upgrade: its changes are already in upstream main (merged upstream); mirror main re-synced

Auto-closed by /recipe-upgrade: its changes are already in upstream main (merged upstream); mirror main re-synced
autonomic-bot closed this pull request 2026-07-13 17:19:43 +00:00
All checks were successful
cc-ci/testme cc-ci: success

Pull request closed

Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/keycloak#4
No description provided.