CVE-2025-9467
Last modified
CVE-2025-9467 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Users of affected versions should apply the following mitigation or upgrade. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product version Vaadin 7.0.0 - 7.7.47 Vaadin 8.0.0 - 8.28.1 Vaadin 14.0.0 - 14.13.0 Vaadin 23.0.0 - 23.6.1 Vaadin 24.0.0 - 24.7.6 Mitigation Upgrade to 7.7.48 Upgrade to 8.28.2 Upgrade to 14.13.1 Upgrade to 23.6.2 Upgrade to 24.7.7 or newer Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 14, 23, 24 version. Artifacts Maven coordinatesVulnerable versionsFixed versioncom.vaadin:vaadin-server 7.0.0 - 7.7.47 ≥7.7.48 com.vaadin:vaadin-server 8.0.0 - 8.28.1 ≥8.28.2 com.vaadin:vaadin 14.0.0 - 14.13.0 ≥14.13.1 com.vaadin:vaadin23.0.0 - 23.6.1 ≥23.6.2 com.vaadin:vaadin24.0.0 - 24.7.6 ≥24.7.7com.vaadin:vaadin-upload-flow 2.0.0 - 14.13.0 ≥14.13.1 com.vaadin:vaadin-upload-flow 23.0.0 - 23.6.1 ≥23.6.2 com.vaadin:vaadin-upload-flow 24.0.0 - 24.7.6 ≥24.7.7
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:L/U:Green
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-9467?
How severe is CVE-2025-9467?
How do I fix CVE-2025-9467?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-9460A maliciously crafted SLDPRT file, when parsed through certa…7.8
- CVE-2025-9461A weakness has been identified in diyhi bbs up to 6.8. The i…7.5
- CVE-2025-9463The Payments Plugin and Checkout Plugin for WooCommerce: Str…6.5
- CVE-2025-9464A security issue exists within ArmorStart® LT that can resul…7.5
- CVE-2025-9465A security issue exists within ArmorStart® LT that can resul…7.5
- CVE-2025-9466A security issue exists within ArmorStart® LT that can resul…7.5
- CVE-2025-9468A security vulnerability has been detected in itsourcecode A…9.8
- CVE-2025-9469A vulnerability was detected in itsourcecode Apartment Manag…9.8
- CVE-2025-9470A flaw has been found in itsourcecode Apartment Management S…9.8
- CVE-2025-9471A vulnerability has been found in itsourcecode Apartment Man…9.8
- CVE-2025-9472A vulnerability was found in itsourcecode Apartment Manageme…9.8
- CVE-2025-9473A security vulnerability has been detected in SourceCodester…9.8
Are you affected by CVE-2025-9467?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
