An issue was found in the redirect_uri validation logic that allows for a bypass of otherwise explicitly allowed hosts.
This issue has been addressed in the following products: Red Hat build of Keycloak 22 Via RHSA-2024:1867 https://access.redhat.com/errata/RHSA-2024:1867