[Bug 297660] net/keycloak: Update to 26.7.2

[email protected]
Newsgroups gmane.os.freebsd.devel.ports.bugs
Message-ID <[email protected]/bugzilla/>
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297660

            Bug ID: 297660
           Summary: net/keycloak: Update to 26.7.2
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
               URL: https://www.keycloak.org/2026/08/keycloak-2672-release
                    d
                OS: Any
            Status: New
          Severity: Affects Only Me
          Priority: ---
         Component: Individual Port(s)
          Assignee: [email protected]
          Reporter: [email protected]
 Attachment #273907 maintainer-approval+
             Flags:

Created attachment 273907
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=273907&action=edit
net/keycloak

Upgrade Keycloak to 26.7.2.

Tested on 15.0-RELEASE and 15.1-RELEASE.

Security:
[CVE-2026-45292] OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C
Baggage Propagation
[CVE-2026-14613] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass via Role
Groups Endpoint
[CVE-2026-59888] and [CVE-2026-59889] Upgrade jackson-databind to 2.21.5 to fix
[CVE-2026-15945] Group hierarchy search discloses hidden parent groups under
FGAP v2 
[CVE-2026-17048] Keycloak Admin REST API Leaks Vault-Resolved Rotated Client
Secrets
[CVE-2026-15571] Predictable account-linking hash enables account takeover via
malicious oidc
[CVE-2026-18963] Unauthenticated account takeover via reset-credentials flow
bypass

-- 
You are receiving this mail because:
You are the assignee for the bug.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.