Skip to content

[GHSA-rhgq-f8x5-j2jc] Keycloak's identity-first login flow exposes user information#7342

Open
dnegreira wants to merge 1 commit intodnegreira/advisory-improvement-7342from
dnegreira-GHSA-rhgq-f8x5-j2jc
Open

[GHSA-rhgq-f8x5-j2jc] Keycloak's identity-first login flow exposes user information#7342
dnegreira wants to merge 1 commit intodnegreira/advisory-improvement-7342from
dnegreira-GHSA-rhgq-f8x5-j2jc

Conversation

@dnegreira
Copy link
Copy Markdown

Updates

  • Affected products

Comments
There are fixes for the 26.4 branch and for 26.6 branch but no new software version release has been made yet with the fixes, that is why I am omitting the fixed version for the time being.
Happy to adjust to add the version as it can be seen below, they are at least labeled in the issue.
The fixes should appear on 26.4.12 and 26.6.1 future keycloak releases.

commit related to the 26.6 branch: keycloak/keycloak@b4558a8

commit related to the 26.4 branch: keycloak/keycloak@b137016

Upstream issue also shows the versions in the labels where the expected fixed releases are keycloak/keycloak#47619

@github-actions github-actions bot changed the base branch from main to dnegreira/advisory-improvement-7342 April 9, 2026 07:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant