# Keycloak 26.5.4 released

DevFeed: [Keycloak 26.5.4 released](<https://devfeed.tech/articles/keycloak-26-5-4-released-31756.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/02/keycloak-2654-released>)

Author: Keycloak Team

Published: 2026-02-20T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [Security](<https://devfeed.tech/topics/security.md>), [saml](<https://devfeed.tech/topics/saml.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [upgrade](<https://devfeed.tech/topics/upgrade.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

## AI overview

Keycloak 26.5.4 is released with security fixes, protocol enhancements, and bug fixes. The release includes fixes for SAML, OIDC, authorization, Docker Registry Protocol, organizations, clustering, caching, and related components.

## Source excerpt

To download the release go to Keycloak downloads. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #45646 CVE-2026-1190 - Keycloak SAML brokering: Response delay due to unchecked NotOnOrAfter in SubjectConfirmationData saml #45649 CVE-2026-0707: Keycloak Authorization Header Parsing Leading to Potential Security Control Bypass #45776 CVE-2025-5416 keycloak-core: Keycloak Environment Information #46372 CVE-2026-2575 - Denial of Service due to excessive SAMLRequest decompression saml #46462 CVE-2026-2733 Missing Check on Disabled Client for Docker Registry Protocol Enhancements #46090 New key affinity for session ids Bugs #44488 "Update email" AIA: "Back to Application" URL invokes OIDC callback with missing parameters oidc #45065 Client deletion timeout due to large number of client roles storage #45680 auth_mellon (SAML) authentication fails after upgrade to 26.5.1 (from 26.4.6) saml #45728 Information Disclosure of Client Secret on Unauthenticated Config Endpoint oidc #45874 Disabled organizations still resolve in organization-aware login flows organizations #45966 KeycloakRealmImport: Realm created in DB but not visible in Admin Console until restart operator #45980 Keycloak cluster with 3 nodes and jdbc-ping stack fails to rejoin after temporary network partition infinispan #46100 Makes Database Query on Every Login Page Load Instead of Using Cache infinispan #46150 Move upgrading note for SAML to 26.5.4 docs #46178 Regression: cannot authenticate in keycloak-admin-client adapter/javascript #46290 Incorrect code used error, leading to "400 / Code already used" during Infinispan state transfers infinispan #46303 JWT Authorization Grant: Always getting "Token was issued too far in the past to be used now" for EntraID issued tokens oidc #46312 io.fabric8:docker-maven-plugin:0.40.3:start failed: Cannot invoke "com.google.gson.JsonElement.isJsonNull()" because the return value of "com.google.gso