CVE-2025-3526 is a denial-of-service vulnerability affecting Liferay Portal versions 7.0.0 through 7.4.3.21 and Liferay DXP versions 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions. The vulnerability, rated 7.5 HIGH on CVSS, allows remote attackers to consume system memory by sending crafted HTTP requests that cause the system to save excessive request parameters in the HTTP session. This issue has a low attack complexity and does not require user interaction or privileges. There is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0, <= 7.2CPE matchmatch criteria | cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* | ||
7.3CPE matchmatch criteria | cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:* | ||
7.3CPE matchmatch criteria | cpe:2.3:a:liferay:digital_experience_platform:7.3:update1:*:*:*:*:*:* | ||
7.3CPE matchmatch criteria | cpe:2.3:a:liferay:digital_experience_platform:7.3:update10:*:*:*:*:*:* | ||
7.3CPE matchmatch criteria | cpe:2.3:a:liferay:digital_experience_platform:7.3:update11:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.