26.7.1 is a patch release — security + bug fixes only (no breaking changes, no migrations, no config changes).
Security fixes: CVE-2026-9793 (JWE request object bypass), CVE-2026-4629 (privilege escalation via role mapper injection), CVE-2026-14209 (FGAP v2 user disclosure), CVE-2026-14614 (FGAP client scope assignment bypass), CVE-2026-14615 (FGAP parent group children bypass).
Bug fixes: WebAuthn attachment policy bypass, clustering test, Kustomize Role/RoleBinding, password-reset double-commit, 500 on duplicate organization scope, LiquibaseDBLockProvider format error.
DB migration is automatic (recipe sets KC_SPI_CONNECTIONS_JPA_LEGACY_MIGRATION_STRATEGY=update); back up the MariaDB volume before upgrading as a precaution.
Recipe version label left untouched (10.9.0+26.7.0); operator runs after merge:
abra recipe release keycloak -z
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
## Upgrade: keycloak 26.7.0 → 26.7.1 (patch)
| service | image | current → new |
|---------|-------|---------------|
| app | keycloak/keycloak | 26.7.0 → 26.7.1 |
| db | mariadb | 12.3 (unchanged) |
**Upstream release notes:** app 26.7.0→26.7.1: https://github.com/keycloak/keycloak/releases/tag/26.7.1
26.7.1 is a patch release — security + bug fixes only (no breaking changes, no migrations, no config changes).
Security fixes: CVE-2026-9793 (JWE request object bypass), CVE-2026-4629 (privilege escalation via role mapper injection), CVE-2026-14209 (FGAP v2 user disclosure), CVE-2026-14614 (FGAP client scope assignment bypass), CVE-2026-14615 (FGAP parent group children bypass).
Bug fixes: WebAuthn attachment policy bypass, clustering test, Kustomize Role/RoleBinding, password-reset double-commit, 500 on duplicate organization scope, LiquibaseDBLockProvider format error.
DB migration is automatic (recipe sets `KC_SPI_CONNECTIONS_JPA_LEGACY_MIGRATION_STRATEGY=update`); back up the MariaDB volume before upgrading as a precaution.
Recipe version label left untouched (`10.9.0+26.7.0`); operator runs after merge:
abra recipe release keycloak -z
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Upgrade: keycloak 26.7.0 → 26.7.1 (patch)
Upstream release notes: app 26.7.0→26.7.1: https://github.com/keycloak/keycloak/releases/tag/26.7.1
26.7.1 is a patch release — security + bug fixes only (no breaking changes, no migrations, no config changes).
Security fixes: CVE-2026-9793 (JWE request object bypass), CVE-2026-4629 (privilege escalation via role mapper injection), CVE-2026-14209 (FGAP v2 user disclosure), CVE-2026-14614 (FGAP client scope assignment bypass), CVE-2026-14615 (FGAP parent group children bypass).
Bug fixes: WebAuthn attachment policy bypass, clustering test, Kustomize Role/RoleBinding, password-reset double-commit, 500 on duplicate organization scope, LiquibaseDBLockProvider format error.
DB migration is automatic (recipe sets
KC_SPI_CONNECTIONS_JPA_LEGACY_MIGRATION_STRATEGY=update); back up the MariaDB volume before upgrading as a precaution.Recipe version label left untouched (
10.9.0+26.7.0); operator runs after merge:abra recipe release keycloak -z
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
🌻 cc-ci —
keycloak@0ef3a426✅ passedfull logs · dashboard
Auto-closed by /recipe-upgrade: its changes are already in upstream main (merged upstream); mirror main re-synced
Pull request closed