chore: upgrade keycloak to 26.7.4 #9

Merged
trav merged 1 commits from upgrade-9073e75 into main 2026-09-21 17:43:17 +00:00
Owner

keycloak 26.7.3 → 26.7.4 (app image only)

service image current new
app keycloak/keycloak 26.7.3 26.7.4
db mariadb 12.3 12.3 (unchanged — 13.0 is a MAJOR db bump, deliberately not taken unattended)

Upstream release notes: app 26.7.3→26.7.4: https://github.com/keycloak/keycloak/releases/tag/26.7.4
Migration guide (26.7.4 section): https://www.keycloak.org/docs/latest/upgrading/#migration-changes

Security patch release — 6 CVEs fixed (release notes + deterministic advisory scan agree on the same 6):

  • CVE-2026-90997 (high) — default MySQL/MariaDB row counts make stateless replay gates accept reused artifacts (relevant: this recipe uses KC_DB=mariadb)
  • CVE-2026-79651 — unauthenticated DoS via unbounded locale caching
  • CVE-2026-74909 — incomplete fix: percent-encoded semicolon bypasses matrix parameter stripping in PathMatcher
  • CVE-2026-19607 — username takeover leading to account lockout
  • CVE-2026-17526 — privilege escalation: the "impersonation" role can impersonate a realm administrator
  • CVE-2026-18212 — SAML Redirect DEFLATE helpers leak native zlib state

Also: Quarkus 3.33.3.2, perf fix for a 26.6.2 regression, admin-console sub-group click exception fix.

Operator Action Required

  • 26.7.4 in-patch breaking change (security hardening): Authorization Services resource-URI matching now normalizes matrix parameters (;jsessionid=…, incl. %3B), dot segments (incl. %2E%2E), percent-encoded slashes, duplicate/trailing slashes, and drops query/fragment before matching. If your Authorization Services config distinguishes resources by those URI forms, review resource/policy config after upgrading.
  • No compose/config changes required; DB schema auto-migrates at start (KC_SPI_CONNECTIONS_JPA_LEGACY_MIGRATION_STRATEGY=update).
  • Non-blocking: Keycloak logs deprecation WARNs for KEYCLOAK_ADMIN/KEYCLOAK_ADMIN_PASSWORD (successor: KC_BOOTSTRAP_ADMIN_*) — pre-existing recipe entrypoint behavior, suggested as a separate follow-up.

mariadb pin deliberately unchanged

abra also reports mariadb 12.3 → 13.0, but that is a MAJOR db bump — not taken unattended here; keycloak 26.7.4 has no mariadb version requirement. (Upstream has it as Renovate PR coop-cloud/keycloak#44 if the operator wants to take it deliberately.) This PR's app-tag diff is byte-identical to upstream Renovate PR coop-cloud/keycloak#45.

Recommended release (operator, after merge — this PR does not bump the version label)

abra recipe release keycloak -z

Evidence (live feedback before CI)

Deployed this branch head (9073e75) with --chaos on the cc-ci CI server under dev-keycloak.ci.commoninternet.net: Keycloak 26.7.4 on JVM (powered by Quarkus 3.33.3.2) started in 26.600s, master realm initialized, Liquibase schema init clean on mariadb 12.3, HTTPS through the proxy 302 on / and 200 on /admin/master/console/. Dev deploy torn down and verified removed afterwards.

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

## keycloak 26.7.3 → 26.7.4 (app image only) | service | image | current | new | |---------|-------|---------|-----| | app | keycloak/keycloak | 26.7.3 | **26.7.4** | | db | mariadb | 12.3 | 12.3 (unchanged — 13.0 is a MAJOR db bump, deliberately not taken unattended) | **Upstream release notes:** app 26.7.3→26.7.4: https://github.com/keycloak/keycloak/releases/tag/26.7.4 Migration guide (26.7.4 section): https://www.keycloak.org/docs/latest/upgrading/#migration-changes Security patch release — **6 CVEs fixed** (release notes + deterministic advisory scan agree on the same 6): - CVE-2026-90997 (high) — default MySQL/MariaDB row counts make stateless replay gates accept reused artifacts (relevant: this recipe uses `KC_DB=mariadb`) - CVE-2026-79651 — unauthenticated DoS via unbounded locale caching - CVE-2026-74909 — incomplete fix: percent-encoded semicolon bypasses matrix parameter stripping in PathMatcher - CVE-2026-19607 — username takeover leading to account lockout - CVE-2026-17526 — privilege escalation: the "impersonation" role can impersonate a realm administrator - CVE-2026-18212 — SAML Redirect DEFLATE helpers leak native zlib state Also: Quarkus 3.33.3.2, perf fix for a 26.6.2 regression, admin-console sub-group click exception fix. ### Operator Action Required - **26.7.4 in-patch breaking change (security hardening):** Authorization Services resource-URI matching now normalizes matrix parameters (`;jsessionid=…`, incl. `%3B`), dot segments (incl. `%2E%2E`), percent-encoded slashes, duplicate/trailing slashes, and drops query/fragment before matching. If your Authorization Services config distinguishes resources by those URI forms, review resource/policy config after upgrading. - No compose/config changes required; DB schema auto-migrates at start (`KC_SPI_CONNECTIONS_JPA_LEGACY_MIGRATION_STRATEGY=update`). - Non-blocking: Keycloak logs deprecation WARNs for `KEYCLOAK_ADMIN`/`KEYCLOAK_ADMIN_PASSWORD` (successor: `KC_BOOTSTRAP_ADMIN_*`) — pre-existing recipe entrypoint behavior, suggested as a separate follow-up. ### mariadb pin deliberately unchanged abra also reports `mariadb` 12.3 → 13.0, but that is a MAJOR db bump — not taken unattended here; keycloak 26.7.4 has no mariadb version requirement. (Upstream has it as Renovate PR coop-cloud/keycloak#44 if the operator wants to take it deliberately.) This PR's app-tag diff is byte-identical to upstream Renovate PR coop-cloud/keycloak#45. ### Recommended release (operator, after merge — this PR does not bump the version label) abra recipe release keycloak -z ### Evidence (live feedback before CI) Deployed this branch head (`9073e75`) with `--chaos` on the cc-ci CI server under `dev-keycloak.ci.commoninternet.net`: `Keycloak 26.7.4 on JVM (powered by Quarkus 3.33.3.2) started in 26.600s`, master realm initialized, Liquibase schema init clean on mariadb 12.3, HTTPS through the proxy 302 on `/` and 200 on `/admin/master/console/`. Dev deploy torn down and verified removed afterwards. Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-09-18 03:04:54 +00:00
autonomic-bot requested review from trav 2026-09-18 03:04:54 +00:00
autonomic-bot requested review from notplants 2026-09-18 03:04:54 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — keycloak @ 9073e75e ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `keycloak` @ `9073e75e` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1366/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1366) [![level](https://ci.commoninternet.net/runs/1366/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1366) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1366) · [dashboard](https://ci.commoninternet.net/)
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — keycloak @ 9073e75e ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `keycloak` @ `9073e75e` ✅ **passed** [![cc-ci result card](https://ci.autonomic.zone/runs/1/summary.png)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/1) [![level](https://ci.autonomic.zone/runs/1/badge.svg)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/1) [full logs](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/1) · [dashboard](https://ci.autonomic.zone/)
trav merged commit 3f03fd23c9 into main 2026-09-21 17:43:17 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/keycloak#9