CVE-2025-5802

MEDIUMCVSS 5.3/10EPSS 0.25%

Last modified

CVE-2025-5802 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explicitly indicates the username is already in use. This behavior allows an attacker to discover valid usernames within the system. EPSS estimates a 0.25% chance of exploitation in the next 30 days.

Description

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explicitly indicates the username is already in use. This behavior allows an attacker to discover valid usernames within the system. The discovery of valid usernames can facilitate subsequent attacks such as brute force, social engineering, and targeted phishing campaigns.

Metrics

EPSS Probability
0.25%

16.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
WSO2WSO2 API Manager< 3.1.0; >= 3.1.0, < 3.1.0.354; >= 3.2.0, < 3.2.0.458; >= 3.2.0, < 3.2.0.478; >= 3.2.1, < 3.2.1.96; >= 4.0.0, < 4.0.0.379; >= 4.1.0, < 4.1.0.262; >= 4.2.0, < 4.2.0.200; >= 4.3.0, < 4.3.0.112; >= 4.4.0, < 4.4.0.72; >= 4.5.0, < 4.5.0.55; >= 4.6.0, < 4.6.0.17
WSO2WSO2 API Control Plane< 4.5.0; >= 4.5.0, < 4.5.0.56; >= 4.6.0, < 4.6.0.18
WSO2WSO2 Universal Gateway< 4.5.0; >= 4.5.0, < 4.5.0.55; >= 4.6.0, < 4.6.0.17
WSO2WSO2 Traffic Manager< 4.5.0; >= 4.5.0, < 4.5.0.54; >= 4.6.0, < 4.6.0.17
WSO2WSO2 Identity Server< 5.10.0; >= 5.10.0, < 5.10.0.383; >= 5.11.0, < 5.11.0.430; >= 6.0.0, < 6.0.0.257; >= 6.1.0, < 6.1.0.234; >= 6.1.0, < 6.1.0.257; >= 7.0.0, < 7.0.0.133; >= 7.1.0, < 7.1.0.41; >= 7.2.0, < 7.2.0.3
WSO2WSO2 Identity Server as Key Manager< 5.10.0; >= 5.10.0, < 5.10.0.374
WSO2WSO2 Open Banking AM< 2.0.0; >= 2.0.0, < 2.0.0.403
WSO2WSO2 Open Banking IAM< 2.0.0; >= 2.0.0, < 2.0.0.423
WSO2WSO2 Carbon Identity Management Endpoint Util>= 5.17.5, < 5.17.5.332; >= 5.18.187, < 5.18.187.330; >= 5.23.8, < 5.23.8.213; >= 5.25.92, < 5.25.92.167; >= 7.0.78, < 7.0.78.162
WSO2WSO2 Carbon Identity Application Authentication Framework>= 5.17.5, < 5.17.5.332; >= 5.18.187, < 5.18.187.330

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2025-5802?
The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explicitly indicates the username is already in use. This behavior allows an attacker to discover valid usernames within the system. The discovery of valid usernames can facilitate subsequent attacks such as brute force, social engineering, and targeted phishing campaigns.
How severe is CVE-2025-5802?
CVE-2025-5802 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.25% probability of exploitation in the next 30 days.
How do I fix CVE-2025-5802?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-5802?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST