CVE-2025-5802
Last modified
CVE-2025-5802 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explicitly indicates the username is already in use. This behavior allows an attacker to discover valid usernames within the system. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explicitly indicates the username is already in use. This behavior allows an attacker to discover valid usernames within the system. The discovery of valid usernames can facilitate subsequent attacks such as brute force, social engineering, and targeted phishing campaigns.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| WSO2 | WSO2 API Manager | < 3.1.0; >= 3.1.0, < 3.1.0.354; >= 3.2.0, < 3.2.0.458; >= 3.2.0, < 3.2.0.478; >= 3.2.1, < 3.2.1.96; >= 4.0.0, < 4.0.0.379; >= 4.1.0, < 4.1.0.262; >= 4.2.0, < 4.2.0.200; >= 4.3.0, < 4.3.0.112; >= 4.4.0, < 4.4.0.72; >= 4.5.0, < 4.5.0.55; >= 4.6.0, < 4.6.0.17 |
| WSO2 | WSO2 API Control Plane | < 4.5.0; >= 4.5.0, < 4.5.0.56; >= 4.6.0, < 4.6.0.18 |
| WSO2 | WSO2 Universal Gateway | < 4.5.0; >= 4.5.0, < 4.5.0.55; >= 4.6.0, < 4.6.0.17 |
| WSO2 | WSO2 Traffic Manager | < 4.5.0; >= 4.5.0, < 4.5.0.54; >= 4.6.0, < 4.6.0.17 |
| WSO2 | WSO2 Identity Server | < 5.10.0; >= 5.10.0, < 5.10.0.383; >= 5.11.0, < 5.11.0.430; >= 6.0.0, < 6.0.0.257; >= 6.1.0, < 6.1.0.234; >= 6.1.0, < 6.1.0.257; >= 7.0.0, < 7.0.0.133; >= 7.1.0, < 7.1.0.41; >= 7.2.0, < 7.2.0.3 |
| WSO2 | WSO2 Identity Server as Key Manager | < 5.10.0; >= 5.10.0, < 5.10.0.374 |
| WSO2 | WSO2 Open Banking AM | < 2.0.0; >= 2.0.0, < 2.0.0.403 |
| WSO2 | WSO2 Open Banking IAM | < 2.0.0; >= 2.0.0, < 2.0.0.423 |
| WSO2 | WSO2 Carbon Identity Management Endpoint Util | >= 5.17.5, < 5.17.5.332; >= 5.18.187, < 5.18.187.330; >= 5.23.8, < 5.23.8.213; >= 5.25.92, < 5.25.92.167; >= 7.0.78, < 7.0.78.162 |
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | >= 5.17.5, < 5.17.5.332; >= 5.18.187, < 5.18.187.330 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-5802?
How severe is CVE-2025-5802?
How do I fix CVE-2025-5802?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-58014Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Q…4.3
- CVE-2025-58015Exposure of Sensitive System Information to an Unauthorized …7.5
- CVE-2025-58016Missing Authorization vulnerability in Codexpert, Inc CF7 Su…4.3
- CVE-2025-58017Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-58018Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-58019Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-58020Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-58021Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-58022Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-58023Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-58024Improper Control of Filename for Include/Require Statement i…7.5
- CVE-2025-58025Improper Neutralization of Input During Web Page Generation …5.4
Are you affected by CVE-2025-5802?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
