chore: upgrade keycloak to 26.7.3 #8

Open
autonomic-bot wants to merge 1 commits from upgrade-ffa656b into main
Owner

Upgrade keycloak app image 26.7.2 → 26.7.3

service image current → new
app keycloak/keycloak 26.7.2 → 26.7.3
db mariadb 12.3 (unchanged — no newer upstream)

Upstream release notes:

Security (patch release on a security-relevant track): 26.7.3 fixes 21 CVEs — including
CVE-2026-35563 (LDAP cert hostname verification), CVE-2026-16093 (signed-JWT assertion bypass),
CVE-2026-16072 (org managers via stored registration links), CVE-2026-16108 / CVE-2026-16105 /
CVE-2026-16104 / CVE-2026-16106 / CVE-2026-17059 / CVE-2026-18571 (FGAP v2 / admin-Z fine-grained
auth issues), CVE-2026-16089 & CVE-2026-18209 (OIDC authz-code/redirect issues), CVE-2026-18218,
CVE-2026-18215 / CVE-2026-18214 (token-exchange), CVE-2026-18201, CVE-2026-18572, CVE-2026-18573,
CVE-2026-18570, CVE-2026-19729 (incomplete fix of CVE-2026-9083 path traversal), CVE-2026-79652.
The preceding 26.7.2 (already merged upstream into main) fixed 7 including critical CVE-2026-18963
(unauthenticated account takeover via reset-credentials flow bypass). Recipes going straight from a
26.7.1 deploy to 26.7.3 land both batches. Deterministic advisory scan of this window
(26.7.2→26.7.3): 22 CVEs fixed, 0 unjudged.

Operator action required:

  • No migrations or config changes required by the recipe (migration guide checked; the recipe's
    KC_* env is unchanged). Verified live: a --chaos deploy of this exact tree on cc-ci booted
    26.7.3 clean (Keycloak 26.7.3 on JVM, started in ~8s, realm discovery + admin console serving;
    only warnings are pre-existing deprecation notices for KEYCLOAK_ADMIN/KEYCLOAK_ADMIN_PASSWORD).
  • Recommended publish step (after this merges): abra recipe release keycloak -z
    (patch — security/patch-level 26.7.x bump; version label 10.9.2+26.7.2 → next +26.7.3 at
    release time). NOT run here — version label left untouched in this PR.

NOTE: upstream coop-cloud/keycloak already has its own renovate PR (#42) toward 26.7.3; this mirror PR
parallels it (cc-ci mirror reflects true upstream main = 26.7.2 here).

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

**Upgrade keycloak app image 26.7.2 → 26.7.3** | service | image | current → new | |---|---|---| | app | keycloak/keycloak | 26.7.2 → **26.7.3** | | db | mariadb | 12.3 (unchanged — no newer upstream) | **Upstream release notes:** - keycloak/keycloak 26.7.2→26.7.3: https://github.com/keycloak/keycloak/releases/tag/26.7.3 - keycloak/keycloak 26.7.1→26.7.2 (already in main): https://github.com/keycloak/keycloak/releases/tag/26.7.2 **Security (patch release on a security-relevant track):** 26.7.3 fixes 21 CVEs — including CVE-2026-35563 (LDAP cert hostname verification), CVE-2026-16093 (signed-JWT assertion bypass), CVE-2026-16072 (org managers via stored registration links), CVE-2026-16108 / CVE-2026-16105 / CVE-2026-16104 / CVE-2026-16106 / CVE-2026-17059 / CVE-2026-18571 (FGAP v2 / admin-Z fine-grained auth issues), CVE-2026-16089 & CVE-2026-18209 (OIDC authz-code/redirect issues), CVE-2026-18218, CVE-2026-18215 / CVE-2026-18214 (token-exchange), CVE-2026-18201, CVE-2026-18572, CVE-2026-18573, CVE-2026-18570, CVE-2026-19729 (incomplete fix of CVE-2026-9083 path traversal), CVE-2026-79652. The preceding 26.7.2 (already merged upstream into main) fixed 7 including critical CVE-2026-18963 (unauthenticated account takeover via reset-credentials flow bypass). Recipes going straight from a 26.7.1 deploy to 26.7.3 land both batches. Deterministic advisory scan of this window (26.7.2→26.7.3): **22 CVEs fixed**, 0 unjudged. **Operator action required:** - No migrations or config changes required by the recipe (migration guide checked; the recipe's `KC_*` env is unchanged). Verified live: a `--chaos` deploy of this exact tree on cc-ci booted 26.7.3 clean (Keycloak 26.7.3 on JVM, started in ~8s, realm discovery + admin console serving; only warnings are pre-existing deprecation notices for `KEYCLOAK_ADMIN`/`KEYCLOAK_ADMIN_PASSWORD`). - Recommended publish step (after this merges): **`abra recipe release keycloak -z`** (patch — security/patch-level 26.7.x bump; version label `10.9.2+26.7.2` → next `+26.7.3` at release time). NOT run here — version label left untouched in this PR. NOTE: upstream coop-cloud/keycloak already has its own renovate PR (#42) toward 26.7.3; this mirror PR parallels it (cc-ci mirror reflects true upstream main = 26.7.2 here). Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-08-31 19:54:45 +00:00
autonomic-bot requested review from trav 2026-08-31 19:54:45 +00:00
autonomic-bot requested review from notplants 2026-08-31 19:54:45 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-cikeycloak @ ffa656bc passedhttps://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1307

(summary card unavailable — see the run for details.) full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `keycloak` @ `ffa656bc` ✅ **passed** → https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1307 _(summary card unavailable — see the run for details.)_ [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1307) · [dashboard](https://ci.commoninternet.net/)
All checks were successful
cc-ci/testme cc-ci: success
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin upgrade-ffa656b:upgrade-ffa656b
git checkout upgrade-ffa656b
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/keycloak#8