Three moderate, unpatched Keycloak advisories in 26.6.4

  • CVE‑2026‑9689 (GHSA‑wcvj‑vpvw‑9rr5) — redirect‑URI HTTP parameter pollution

  • CVE‑2026‑9798 (GHSA‑q6h7‑xxp7‑7429) — CIBA brute‑force‑protection bypass

  • CVE‑2026‑9793 (GHSA‑p3v8‑fm5p‑v84h) — JWE unsigned‑claims signature bypass

    wondering when these might be closed?

Some of them are resolved in the 26.7.0 release Keycloak 26.7.0 released - Keycloak