chore: upgrade keycloak to 26.7.2 #7

Closed
autonomic-bot wants to merge 1 commits from upgrade-09512d3 into main
Owner

Upgrade keycloak app 26.7.1 → 26.7.2 (patch — security + bugfix release).

Image-tag table

service image current → new
app keycloak/keycloak 26.7.1 → 26.7.2
db mariadb 12.3 (unchanged, up-to-date)

Recipe version label left untouched (per /recipe-upgrade convention).

What's in 26.7.2

Security patch release fixing 7 CVEs (notable account-takeover + FGAP bypasses) plus a Quarkus 3.33.3.1 upgrade:

  • CVE-2026-45292 — OpenTelemetry Java SDK unbounded memory allocation (dependency)
  • CVE-2026-14613 — 26.6.3 FGAP bypass via Role Groups endpoint
  • CVE-2026-59888 + CVE-2026-59889 — jackson-databind 2.21.5
  • CVE-2026-15945 — group hierarchy search discloses hidden parent groups under FGAP v2
  • CVE-2026-17048 — Admin REST API leaks Vault-resolved rotated client secrets (oidc)
  • CVE-2026-15571 — predictable account-linking hash → account takeover via malicious oidc client
  • CVE-2026-18963 — unauthenticated account takeover via reset-credentials flow bypass

Operator Action Required: none — patch release, no breaking changes / migrations / config changes. DB migration is automatic; back up the MariaDB volume before upgrading as a precaution.

Upstream release notes

app keycloak/keycloak 26.7.1→26.7.2: https://github.com/keycloak/keycloak/releases/tag/26.7.2
Upgrading guide: https://www.keycloak.org/docs/latest/upgrading/

Recommended release command (operator, after merge)

abra recipe release keycloak -z

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

**Upgrade keycloak app 26.7.1 → 26.7.2** (patch — security + bugfix release). ## Image-tag table | service | image | current → new | |---------|-------|---------------| | app | keycloak/keycloak | 26.7.1 → 26.7.2 | | db | mariadb | 12.3 (unchanged, up-to-date) | Recipe version label left untouched (per /recipe-upgrade convention). ## What's in 26.7.2 Security patch release fixing **7 CVEs** (notable account-takeover + FGAP bypasses) plus a Quarkus 3.33.3.1 upgrade: - CVE-2026-45292 — OpenTelemetry Java SDK unbounded memory allocation (dependency) - CVE-2026-14613 — 26.6.3 FGAP bypass via Role Groups endpoint - CVE-2026-59888 + CVE-2026-59889 — jackson-databind 2.21.5 - CVE-2026-15945 — group hierarchy search discloses hidden parent groups under FGAP v2 - CVE-2026-17048 — Admin REST API leaks Vault-resolved rotated client secrets (oidc) - CVE-2026-15571 — predictable account-linking hash → account takeover via malicious oidc client - CVE-2026-18963 — unauthenticated account takeover via reset-credentials flow bypass **Operator Action Required:** none — patch release, no breaking changes / migrations / config changes. DB migration is automatic; back up the MariaDB volume before upgrading as a precaution. ## Upstream release notes **app keycloak/keycloak 26.7.1→26.7.2:** https://github.com/keycloak/keycloak/releases/tag/26.7.2 Upgrading guide: https://www.keycloak.org/docs/latest/upgrading/ ## Recommended release command (operator, after merge) abra recipe release keycloak -z Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-08-21 02:37:02 +00:00
autonomic-bot requested review from trav 2026-08-21 02:37:02 +00:00
autonomic-bot requested review from notplants 2026-08-21 02:37:02 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-cikeycloak @ 09512d37 passedhttps://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1293

(summary card unavailable — see the run for details.) full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `keycloak` @ `09512d37` ✅ **passed** → https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1293 _(summary card unavailable — see the run for details.)_ [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1293) · [dashboard](https://ci.commoninternet.net/)
Author
Owner

Auto-closed by /recipe-upgrade: its changes are already in upstream main (merged upstream); mirror main re-synced

Auto-closed by /recipe-upgrade: its changes are already in upstream main (merged upstream); mirror main re-synced
autonomic-bot closed this pull request 2026-08-22 20:18:54 +00:00

Pull request closed

Please reopen this pull request to perform a merge.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/keycloak#7