Skip to content
Oday Bakkour
Back to Knowledge Hub

Keycloak 26.8, Compose 5.6 and Node 26.10 Release Audit

Oday Bakkour profile photo
Oday Bakkour
4 min read
Share
Keycloak 26.8, Compose 5.6 and Node 26.10 Release Audit

Executive Summary

  • Keycloak 26.8.0 (Oct 1): SCIM API and multi-cluster v2 become supported, OID4VCI moves to preview, and login failures now persist in the database by default. See the release.
  • Keycloak 26.7.5 (Sep 30, security): 13 CVEs fixed, including a CIBA lockout bypass (CVE-2026-16103) and SAML redirect parameter pollution (CVE-2026-18217). See the 26.7.5 notes.
  • Docker Compose 5.6.0 (Oct 2): partial support for manually triggered jobs. See the release.
  • Node.js 26.10.0 (Sep 22): new util.throttle(), util.debounce(), crypto.parsePKCS12() and fs.openAsBlobSync(). See the release notes.
  • Still open: Next.js 16.3.8 and 15.5.27 (Sep 30) patch seven advisories, including an image optimization SSRF. Details in the official post.

Keycloak 26.8.0

Keycloak 26.8.0 shipped on October 1. The headline items are the SCIM API and multi-cluster v2 reaching supported status, Client Secret Rotation for zero-downtime rotation, shared identity providers across organizations, and OID4VCI (digital wallet credential issuance) promoted to preview. Token exchange delegation now supports consent and Fine-Grained Admin Permissions.

Plan for these breaking changes before upgrading:

  • The multi-site feature (multi-cluster v1) is deprecated. Migrate to the stateless feature for v2.
  • Login failure data is now stored in the database instead of memory. Expect extra write load on busy realms.
  • New organization IdP links default to the "Unmanaged" membership type, and existing links are migrated to "Managed".
  • The identity provider button section of the login theme was redesigned. Custom themes need updates.
  • Legacy OIDC compatibility modes, the "Full scope allowed" client switch and non-OIDC client registration providers are deprecated.

Read the upgrading guide and the 26.8.0 release page before rolling out. If you run a custom theme, test the login page in staging first.

Keycloak 26.7.5 security fixes

The September 30 patch release fixes 13 vulnerabilities. Several affect common configurations, so treat it as a priority patch if you are still on 26.7.x:

  • CVE-2026-16103: CIBA brute-force lockout bypass at token redemption (an incomplete fix for CVE-2026-9798).
  • CVE-2026-18206 and CVE-2026-18211: client policy and secure-client-uris host matching accepted non-subdomain suffixes and localhost-prefixed attacker domains.
  • CVE-2026-18217: SAML Redirect Binding parameter pollution.
  • CVE-2026-89298: confidential client secret disclosed to the view-clients role through Client Registration GET.
  • CVE-2026-88770: Device Authorization Grant issued tokens to brute-force-locked accounts.
  • CVE-2026-93999: token-exchange refresh kept issuing tokens for a disabled audience client.

The release also bumps dependencies with their own CVEs (BouncyCastle, FreeMarker, owasp-java-html-sanitizer). The full list is in the 26.7.5 release notes. Keycloak 26.7.4 (Sep 16) fixed six more issues, so skipping straight to 26.7.5 or 26.8.0 covers both.

Docker Compose 5.6.0

Compose 5.6.0 (October 2) adds partial support for jobs: only manually triggered jobs work for now, and scheduled jobs are not available yet. It also improves provider services (network relay), build progress handling, watch rebuild coalescing, port publisher stability on dual-stack hosts, and dangling image cleanup during down. See the Compose releases page.

Check the release notes for the exact spec syntax before using jobs. As a rough shape, a job is a service that you run on demand rather than keep alive:

compose.yaml
# compose.yaml (illustrative; confirm syntax in the 5.6.0 release notes)
services:
  web:
    image: myapp:latest
jobs:
  migrate:
    image: myapp:latest
    command: ["npm", "run", "migrate"]

Node.js 26.10.0 and the 22.23.3 LTS

Node.js 26.10.0 (Current, September 22) adds several utilities. util.throttle() and util.debounce() remove a common reason to pull in a helper package, crypto.parsePKCS12() parses PKCS#12 bundles, and fs.openAsBlobSync() opens files as Blob objects synchronously. SQLite now binds undefined to NULL, and Hybrid KEMs were added to the Web Cryptography API. Node.js 22.23.3 LTS shipped on September 23, and 24.21.0 LTS on September 9.

debounce.mjs
import { debounce } from 'node:util';

const save = debounce(() => console.log('saved'), 250);
save(); save(); save(); // logs once, 250 ms after the last call

The signature above follows the release notes' description of util.debounce(). Verify argument order against the 26.10.0 notes before depending on it. These APIs are on the Current line, so production services on LTS will not see them yet.

Next.js: still worth patching

If you missed it: Next.js 16.3.8 and 15.5.27 fix a high-severity SSRF in Image Optimization (CVE-2026-94483), several cache poisoning and leakage issues, and a dev-server MCP endpoint leak (CVE-2026-94486). The SSRF only applies if you configure images.remotePatterns. Next.js 16.3.6 and 15.5.26 earlier addressed a critical ImageResponse remote code execution issue (GHSA-vcvr-r3jv-pc5j). Read the full September 2026 security release.

terminal
npm install [email protected]   # 16.3 line
npm install [email protected]  # 15.5 line

What to do today

  • Upgrade Keycloak to 26.7.5 at minimum, or to 26.8.0 after reviewing the breaking changes.
  • Move Next.js apps to 16.3.8 or 15.5.27.
  • Try Compose 5.6.0 jobs in a dev environment, and keep production on a pinned Compose version until the feature matures.
Add Oday Bakkour as a preferred source on Google

Comments

Share your thoughts and join the conversation

Leave a Comment

Loading comments...
RELATED
Keycloak 26.8, Compose 5.6 and Node 26.10 Release Audit | Oday Bakkour