Change8

26.2.2

📦 keycloakView on GitHub →
1 features🐛 3 fixes

Summary

This release introduces configuration for the distribution startup timeout and resolves several critical bugs, including security vulnerabilities related to 2FA bypass and hostname verification.

Migration Steps

  1. Refer to the migration guide for a complete list of changes: file:/home/runner/work/keycloak-rel/keycloak-rel/target/web/docs/latest/upgrading/#migration-changes

✨ New Features

  • #39142 Make distribution startup timeout configurable in testsuite.

🐛 Bug Fixes

  • #39125 [Keycloak CI] - FIPS UT - Run crypto tests in ci.
  • #39349 CVE-2025-3910 Two factor authentication bypass.
  • #39350 CVE-2025-3501 Keycloak hostname verification.