-
CVE‑2026‑9689 (GHSA‑wcvj‑vpvw‑9rr5) — redirect‑URI HTTP parameter pollution
-
CVE‑2026‑9798 (GHSA‑q6h7‑xxp7‑7429) — CIBA brute‑force‑protection bypass
-
CVE‑2026‑9793 (GHSA‑p3v8‑fm5p‑v84h) — JWE unsigned‑claims signature bypass
wondering when these might be closed?
Some of them are resolved in the 26.7.0 release Keycloak 26.7.0 released - Keycloak