Chapter 4. Updates for 26.2.15


This release contains several fixed issues.

When the OIDC token endpoint request (or OAuth2 token endpoint request) is sent, a new limit exists for the maximum length of every OIDC/OAuth2 parameter. The maximum length of each parameter is 4,000 characters, which is aligned with the same limit, which already exists for the parameters sent to OIDC/OAuth authentication request.

If you want to increase or lower those numbers, start the server with the option req-params-default-max-size for the default maximum length of the OIDC/OAuth2 parameters, or you can use something such as req-params-max-size for one specific parameter. For more details, see the login-protocol provider configuration in the All Provider Configuration Guide.

4.2. CVE fixes

The following bug fix advisories list the fixed CVEs for the ZIP file distribution and the container image:

Red Hat logoGithubredditYoutubeTwitter

Learn

Try, buy, & sell

Communities

About Red Hat

We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

Making open source more inclusive

Red Hat is committed to replacing problematic language in our code, documentation, and web properties. For more details, see the Red Hat Blog.

About Red Hat Documentation

Legal Notice

Theme

© 2026 Red Hat
Back to top