This major release comes with a blog post about a CVE: https://www.keycloak.org/2021/12/cve.html Not all versions are affected but they're suggesting that people upgrade soon.