CVE Alert: CVE-2025-32959

Vulnerability Summary: CVE-2025-32959
CUBA Platform is a high level framework for enterprise applications development. Prior to version 7.2.23, the local file storage implementation does not restrict the size of uploaded files. An attacker could exploit this by uploading excessively large files, potentially causing the server to run out of space and return HTTP 500 error, resulting in a denial of service. This issue has been patched in version 7.2.23. A workaround is provided on the Jmix documentation website.
Affected Endpoints:
No affected endpoints listed.
Published Date:
4/22/2025, 6:16:00 PM
⚠️ CVSS Score:
Exploit Status:
Not ExploitedReferences:
- https://docs.jmix.io/jmix/files-vulnerabilities.html
- https://docs.jmix.io/jmix/files-vulnerabilities.html#disable-files-endpoint-in-cuba-application
- https://github.com/cuba-platform/cuba/commit/42b6c00fd0572b8e52ae31afd1babc827a3161a1
- https://github.com/cuba-platform/cuba/security/advisories/GHSA-w3mp-6vrj-875g
- https://github.com/jmix-framework/jmix/security/advisories/GHSA-f3gv-cwwh-758m
Recommended Action:
No proposed action available. Please refer to vendor documentation for updates.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below
To keep up to date follow us on the below channels.