CVE-2025-2529
Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application using Ehcache utilizes keys sourced from (malicious) external parties in an unfiltered/unsalted way.
Scoring
- Severity
- LOW
- CVSS base score
- 2.9
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.19%
- CWE
- CWE-228
- Published
- 2025-10-15
- Last modified
- 2026-03-12
Affected products
- IBM Terracotta
- IBM Terracotta
Weakness type
Related vulnerabilities
- CVE-2026-50103 — Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850
- CVE-2025-59174 — Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an...
- CVE-2026-25657 — Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability
- CVE-2026-42100 — DoS in Sparx Pro Cloud Server
- CVE-2026-34232 — Firebird: DoS via `op_response` packet from client
- CVE-2024-53828 — Ericsson Packet Core Controller (PCC) - Improper Handling of Syntactically Invalid Structure Vulnerability
- CVE-2026-20125 — A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release...
- CVE-2025-47736 — dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash...