CVE-2026-19607 — username takeover leading to account lockout
CVE-2026-17526 — privilege escalation: the "impersonation" role can impersonate a realm administrator
CVE-2026-18212 — SAML Redirect DEFLATE helpers leak native zlib state
Also: Quarkus 3.33.3.2, perf fix for a 26.6.2 regression, admin-console sub-group click exception fix.
Operator Action Required
26.7.4 in-patch breaking change (security hardening): Authorization Services resource-URI matching now normalizes matrix parameters (;jsessionid=…, incl. %3B), dot segments (incl. %2E%2E), percent-encoded slashes, duplicate/trailing slashes, and drops query/fragment before matching. If your Authorization Services config distinguishes resources by those URI forms, review resource/policy config after upgrading.
No compose/config changes required; DB schema auto-migrates at start (KC_SPI_CONNECTIONS_JPA_LEGACY_MIGRATION_STRATEGY=update).
Non-blocking: Keycloak logs deprecation WARNs for KEYCLOAK_ADMIN/KEYCLOAK_ADMIN_PASSWORD (successor: KC_BOOTSTRAP_ADMIN_*) — pre-existing recipe entrypoint behavior, suggested as a separate follow-up.
mariadb pin deliberately unchanged
abra also reports mariadb 12.3 → 13.0, but that is a MAJOR db bump — not taken unattended here; keycloak 26.7.4 has no mariadb version requirement. (Upstream has it as Renovate PR coop-cloud/keycloak#44 if the operator wants to take it deliberately.) This PR's app-tag diff is byte-identical to upstream Renovate PR coop-cloud/keycloak#45.
Recommended release (operator, after merge — this PR does not bump the version label)
abra recipe release keycloak -z
Evidence (live feedback before CI)
Deployed this branch head (9073e75) with --chaos on the cc-ci CI server under dev-keycloak.ci.commoninternet.net: Keycloak 26.7.4 on JVM (powered by Quarkus 3.33.3.2) started in 26.600s, master realm initialized, Liquibase schema init clean on mariadb 12.3, HTTPS through the proxy 302 on / and 200 on /admin/master/console/. Dev deploy torn down and verified removed afterwards.
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
## keycloak 26.7.3 → 26.7.4 (app image only)
| service | image | current | new |
|---------|-------|---------|-----|
| app | keycloak/keycloak | 26.7.3 | **26.7.4** |
| db | mariadb | 12.3 | 12.3 (unchanged — 13.0 is a MAJOR db bump, deliberately not taken unattended) |
**Upstream release notes:** app 26.7.3→26.7.4: https://github.com/keycloak/keycloak/releases/tag/26.7.4
Migration guide (26.7.4 section): https://www.keycloak.org/docs/latest/upgrading/#migration-changes
Security patch release — **6 CVEs fixed** (release notes + deterministic advisory scan agree on the same 6):
- CVE-2026-90997 (high) — default MySQL/MariaDB row counts make stateless replay gates accept reused artifacts (relevant: this recipe uses `KC_DB=mariadb`)
- CVE-2026-79651 — unauthenticated DoS via unbounded locale caching
- CVE-2026-74909 — incomplete fix: percent-encoded semicolon bypasses matrix parameter stripping in PathMatcher
- CVE-2026-19607 — username takeover leading to account lockout
- CVE-2026-17526 — privilege escalation: the "impersonation" role can impersonate a realm administrator
- CVE-2026-18212 — SAML Redirect DEFLATE helpers leak native zlib state
Also: Quarkus 3.33.3.2, perf fix for a 26.6.2 regression, admin-console sub-group click exception fix.
### Operator Action Required
- **26.7.4 in-patch breaking change (security hardening):** Authorization Services resource-URI matching now normalizes matrix parameters (`;jsessionid=…`, incl. `%3B`), dot segments (incl. `%2E%2E`), percent-encoded slashes, duplicate/trailing slashes, and drops query/fragment before matching. If your Authorization Services config distinguishes resources by those URI forms, review resource/policy config after upgrading.
- No compose/config changes required; DB schema auto-migrates at start (`KC_SPI_CONNECTIONS_JPA_LEGACY_MIGRATION_STRATEGY=update`).
- Non-blocking: Keycloak logs deprecation WARNs for `KEYCLOAK_ADMIN`/`KEYCLOAK_ADMIN_PASSWORD` (successor: `KC_BOOTSTRAP_ADMIN_*`) — pre-existing recipe entrypoint behavior, suggested as a separate follow-up.
### mariadb pin deliberately unchanged
abra also reports `mariadb` 12.3 → 13.0, but that is a MAJOR db bump — not taken unattended here; keycloak 26.7.4 has no mariadb version requirement. (Upstream has it as Renovate PR coop-cloud/keycloak#44 if the operator wants to take it deliberately.) This PR's app-tag diff is byte-identical to upstream Renovate PR coop-cloud/keycloak#45.
### Recommended release (operator, after merge — this PR does not bump the version label)
abra recipe release keycloak -z
### Evidence (live feedback before CI)
Deployed this branch head (`9073e75`) with `--chaos` on the cc-ci CI server under `dev-keycloak.ci.commoninternet.net`: `Keycloak 26.7.4 on JVM (powered by Quarkus 3.33.3.2) started in 26.600s`, master realm initialized, Liquibase schema init clean on mariadb 12.3, HTTPS through the proxy 302 on `/` and 200 on `/admin/master/console/`. Dev deploy torn down and verified removed afterwards.
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
keycloak 26.7.3 → 26.7.4 (app image only)
Upstream release notes: app 26.7.3→26.7.4: https://github.com/keycloak/keycloak/releases/tag/26.7.4
Migration guide (26.7.4 section): https://www.keycloak.org/docs/latest/upgrading/#migration-changes
Security patch release — 6 CVEs fixed (release notes + deterministic advisory scan agree on the same 6):
KC_DB=mariadb)Also: Quarkus 3.33.3.2, perf fix for a 26.6.2 regression, admin-console sub-group click exception fix.
Operator Action Required
;jsessionid=…, incl.%3B), dot segments (incl.%2E%2E), percent-encoded slashes, duplicate/trailing slashes, and drops query/fragment before matching. If your Authorization Services config distinguishes resources by those URI forms, review resource/policy config after upgrading.KC_SPI_CONNECTIONS_JPA_LEGACY_MIGRATION_STRATEGY=update).KEYCLOAK_ADMIN/KEYCLOAK_ADMIN_PASSWORD(successor:KC_BOOTSTRAP_ADMIN_*) — pre-existing recipe entrypoint behavior, suggested as a separate follow-up.mariadb pin deliberately unchanged
abra also reports
mariadb12.3 → 13.0, but that is a MAJOR db bump — not taken unattended here; keycloak 26.7.4 has no mariadb version requirement. (Upstream has it as Renovate PR coop-cloud/keycloak#44 if the operator wants to take it deliberately.) This PR's app-tag diff is byte-identical to upstream Renovate PR coop-cloud/keycloak#45.Recommended release (operator, after merge — this PR does not bump the version label)
abra recipe release keycloak -z
Evidence (live feedback before CI)
Deployed this branch head (
9073e75) with--chaoson the cc-ci CI server underdev-keycloak.ci.commoninternet.net:Keycloak 26.7.4 on JVM (powered by Quarkus 3.33.3.2) started in 26.600s, master realm initialized, Liquibase schema init clean on mariadb 12.3, HTTPS through the proxy 302 on/and 200 on/admin/master/console/. Dev deploy torn down and verified removed afterwards.Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
🌻 cc-ci —
keycloak@9073e75e✅ passedfull logs · dashboard
!testme
🌻 cc-ci —
keycloak@9073e75e✅ passedfull logs · dashboard