CVE-2025-5416: Red Hat Keycloak

Low severity, CVSS 2.7. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.

Affected products

  • Red Hat Keycloak: affected versions not specified

Published 2025-06-20. Last modified 2026-06-17.