A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-24573