High severity authorization #vulnerability in Keycloak: 1. Of course it's because of JWT 2. If a project with a sole purpose is authn/authz is getting #JWT wrong, you probably are too. https://github.com/advisories/GHSA-hcvw-475w-8g7p