Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-31672

18
FAUCET Score

CVE-2025-31672 is an Improper Input Validation vulnerability in Apache POI, affecting versions prior to 5.4.0, including products like Apache Active IQ Unified Manager and NetApp POI. It arises from the parsing of OOXML files (e.g., .xlsx, .docx) where malicious users can embed duplicate zip entry names, leading to inconsistent data interpretation across different products. Rated with a CVSS score of 5.3 (Medium), the vulnerability has a network attack vector and low attack complexity, requiring no user interaction or privileges. Its potential impact is limited to data integrity (I:L), as different products might read varying data from the malformed file, but does not affect confidentiality or availability. Currently, there is no evidence of active exploitation, and no public exploit code or Metasploit/Nuclei modules are available. Community discussion and media coverage are minimal, indicating low public attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.4.0CPE matchmatch criteria
cpe:2.3:a:apache:poi:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.29%
Probability of exploitation in next 30 days
EPSS Percentile
67.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0129 is in the 47th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

gcppatch availablevia llm_extracted
View patch
mavenpatch availablevia ghsa
Product: org.apache.poi:poi-ooxmlFixed in: 5.4.0
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apicurio Registry 3Fixed in: poi-ooxml
redhatvendor investigatingvia redhat_api
Product: Red Hat build of OptaPlanner 8Fixed in: poi-ooxml
redhatvendor investigatingvia redhat_api
Product: Red Hat Fuse 7Fixed in: poi-ooxml
redhatvendor investigatingvia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: poi-ooxml
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: poi-ooxml
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: poi-ooxml
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: poi-ooxml
redhatvendor investigatingvia redhat_api
Product: Red Hat Process Automation 7Fixed in: poi-ooxml
redhatvendor investigatingvia redhat_api
Product: streams for Apache KafkaFixed in: poi-ooxml
redhatvendor investigatingvia redhat_api
Product: streams for Apache Kafka 2Fixed in: poi-ooxml
redhatvendor investigatingvia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: poi-ooxml

Vendor Advisories (3)

gcpllm-gcp-e028ccdedcbc6cccCRITICAL

HP Device Manager Vulnerability Update (5.0.16)

Mar 9, 2026
mavenGHSA-gmg8-593g-7mv3medium

Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing

Apr 9, 2025
redhatCVE-2025-31672Moderate

org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names

Apr 9, 2025

References

security.netapp.com / advisory/ntap-20250523-0004
Third Party Advisory
openwall.com / lists/oss-security/2025/04/08/2
Mailing ListThird Party Advisory
bz.apache.org / bugzilla/show_bug.cgi
Permissions Required
lists.apache.org / thread/k14w8vcjqy4h34hh5kzldko78kpylkq5
Mailing ListVendor Advisory