A flaw was found in Keycloak's redirect_uri validation logic. This issue may allow bypassing the allwed path in a redirect URIs that use a wilcard. A successful attack may lead to the theft of an access token if the attacker controls another path on the same web server.