High severity authorization #vulnerability in Keycloak:1. Of course it's because of JWT2. If a project with a sole purpose is authn/authz is getting #JWT wrong, you probably are too.https://github.com/advisories/GHSA-hcvw-475w-8g7p
#Keycloak CVE-2026-1529: "lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access."https://access.redhat.com/security/cve/cve-2026-1529#JWT