Security (patch release on a security-relevant track): 26.7.3 fixes 21 CVEs — including
CVE-2026-35563 (LDAP cert hostname verification), CVE-2026-16093 (signed-JWT assertion bypass),
CVE-2026-16072 (org managers via stored registration links), CVE-2026-16108 / CVE-2026-16105 /
CVE-2026-16104 / CVE-2026-16106 / CVE-2026-17059 / CVE-2026-18571 (FGAP v2 / admin-Z fine-grained
auth issues), CVE-2026-16089 & CVE-2026-18209 (OIDC authz-code/redirect issues), CVE-2026-18218,
CVE-2026-18215 / CVE-2026-18214 (token-exchange), CVE-2026-18201, CVE-2026-18572, CVE-2026-18573,
CVE-2026-18570, CVE-2026-19729 (incomplete fix of CVE-2026-9083 path traversal), CVE-2026-79652.
The preceding 26.7.2 (already merged upstream into main) fixed 7 including critical CVE-2026-18963
(unauthenticated account takeover via reset-credentials flow bypass). Recipes going straight from a
26.7.1 deploy to 26.7.3 land both batches. Deterministic advisory scan of this window
(26.7.2→26.7.3): 22 CVEs fixed, 0 unjudged.
Operator action required:
No migrations or config changes required by the recipe (migration guide checked; the recipe's KC_* env is unchanged). Verified live: a --chaos deploy of this exact tree on cc-ci booted
26.7.3 clean (Keycloak 26.7.3 on JVM, started in ~8s, realm discovery + admin console serving;
only warnings are pre-existing deprecation notices for KEYCLOAK_ADMIN/KEYCLOAK_ADMIN_PASSWORD).
Recommended publish step (after this merges): abra recipe release keycloak -z
(patch — security/patch-level 26.7.x bump; version label 10.9.2+26.7.2 → next +26.7.3 at
release time). NOT run here — version label left untouched in this PR.
NOTE: upstream coop-cloud/keycloak already has its own renovate PR (#42) toward 26.7.3; this mirror PR
parallels it (cc-ci mirror reflects true upstream main = 26.7.2 here).
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
**Upgrade keycloak app image 26.7.2 → 26.7.3**
| service | image | current → new |
|---|---|---|
| app | keycloak/keycloak | 26.7.2 → **26.7.3** |
| db | mariadb | 12.3 (unchanged — no newer upstream) |
**Upstream release notes:**
- keycloak/keycloak 26.7.2→26.7.3: https://github.com/keycloak/keycloak/releases/tag/26.7.3
- keycloak/keycloak 26.7.1→26.7.2 (already in main): https://github.com/keycloak/keycloak/releases/tag/26.7.2
**Security (patch release on a security-relevant track):** 26.7.3 fixes 21 CVEs — including
CVE-2026-35563 (LDAP cert hostname verification), CVE-2026-16093 (signed-JWT assertion bypass),
CVE-2026-16072 (org managers via stored registration links), CVE-2026-16108 / CVE-2026-16105 /
CVE-2026-16104 / CVE-2026-16106 / CVE-2026-17059 / CVE-2026-18571 (FGAP v2 / admin-Z fine-grained
auth issues), CVE-2026-16089 & CVE-2026-18209 (OIDC authz-code/redirect issues), CVE-2026-18218,
CVE-2026-18215 / CVE-2026-18214 (token-exchange), CVE-2026-18201, CVE-2026-18572, CVE-2026-18573,
CVE-2026-18570, CVE-2026-19729 (incomplete fix of CVE-2026-9083 path traversal), CVE-2026-79652.
The preceding 26.7.2 (already merged upstream into main) fixed 7 including critical CVE-2026-18963
(unauthenticated account takeover via reset-credentials flow bypass). Recipes going straight from a
26.7.1 deploy to 26.7.3 land both batches. Deterministic advisory scan of this window
(26.7.2→26.7.3): **22 CVEs fixed**, 0 unjudged.
**Operator action required:**
- No migrations or config changes required by the recipe (migration guide checked; the recipe's
`KC_*` env is unchanged). Verified live: a `--chaos` deploy of this exact tree on cc-ci booted
26.7.3 clean (Keycloak 26.7.3 on JVM, started in ~8s, realm discovery + admin console serving;
only warnings are pre-existing deprecation notices for `KEYCLOAK_ADMIN`/`KEYCLOAK_ADMIN_PASSWORD`).
- Recommended publish step (after this merges): **`abra recipe release keycloak -z`**
(patch — security/patch-level 26.7.x bump; version label `10.9.2+26.7.2` → next `+26.7.3` at
release time). NOT run here — version label left untouched in this PR.
NOTE: upstream coop-cloud/keycloak already has its own renovate PR (#42) toward 26.7.3; this mirror PR
parallels it (cc-ci mirror reflects true upstream main = 26.7.2 here).
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Upgrade keycloak app image 26.7.2 → 26.7.3
Upstream release notes:
Security (patch release on a security-relevant track): 26.7.3 fixes 21 CVEs — including
CVE-2026-35563 (LDAP cert hostname verification), CVE-2026-16093 (signed-JWT assertion bypass),
CVE-2026-16072 (org managers via stored registration links), CVE-2026-16108 / CVE-2026-16105 /
CVE-2026-16104 / CVE-2026-16106 / CVE-2026-17059 / CVE-2026-18571 (FGAP v2 / admin-Z fine-grained
auth issues), CVE-2026-16089 & CVE-2026-18209 (OIDC authz-code/redirect issues), CVE-2026-18218,
CVE-2026-18215 / CVE-2026-18214 (token-exchange), CVE-2026-18201, CVE-2026-18572, CVE-2026-18573,
CVE-2026-18570, CVE-2026-19729 (incomplete fix of CVE-2026-9083 path traversal), CVE-2026-79652.
The preceding 26.7.2 (already merged upstream into main) fixed 7 including critical CVE-2026-18963
(unauthenticated account takeover via reset-credentials flow bypass). Recipes going straight from a
26.7.1 deploy to 26.7.3 land both batches. Deterministic advisory scan of this window
(26.7.2→26.7.3): 22 CVEs fixed, 0 unjudged.
Operator action required:
KC_*env is unchanged). Verified live: a--chaosdeploy of this exact tree on cc-ci booted26.7.3 clean (Keycloak 26.7.3 on JVM, started in ~8s, realm discovery + admin console serving;
only warnings are pre-existing deprecation notices for
KEYCLOAK_ADMIN/KEYCLOAK_ADMIN_PASSWORD).abra recipe release keycloak -z(patch — security/patch-level 26.7.x bump; version label
10.9.2+26.7.2→ next+26.7.3atrelease time). NOT run here — version label left untouched in this PR.
NOTE: upstream coop-cloud/keycloak already has its own renovate PR (#42) toward 26.7.3; this mirror PR
parallels it (cc-ci mirror reflects true upstream main = 26.7.2 here).
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
🌻 cc-ci —
keycloak@ffa656bc✅ passed → https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1307(summary card unavailable — see the run for details.) full logs · dashboard
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.