---
id: CVE-2023-25499
title: >-
  When adding non-visible components to the UI in server side, content is sent
  to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0,
  15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and
  24.1.0.alpha1…
summary: >-
  When adding non-visible components to the UI in server side, content is sent
  to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0,
  15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and
  24.1.0.alpha1…
severity: medium
cvss: 5.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
vendor: vaadin
product: vaadin
affected:
  - 'vaadin >= 10.0.0, < 10.0.23'
  - 'vaadin >= 11.0.0, < 14.10.1'
  - 'vaadin >= 15.0.0, <= 22.0.28'
  - 'vaadin >= 23.0.0, < 23.3.13'
  - 'vaadin >= 24.0.0, < 24.0.6'
  - vaadin = 24.1.0
patched:
  - vaadin 24.0.6
published: '2023-06-22'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T16:17:04.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-25499'
references:
  - url: 'https://github.com/vaadin/flow/pull/15885'
    label: security@vaadin.com
  - url: 'https://vaadin.com/security/CVE-2023-25499'
    label: security@vaadin.com
  - url: 'https://github.com/vaadin/flow/pull/15885'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://vaadin.com/security/CVE-2023-25499'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
epss: 0.0058
epssPercentile: 0.4528
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2024-12-05T19:58:40.795727Z'
ingestedAt: '2026-09-14T15:23:07.409Z'
---

## Overview

When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1 to 24.1.0.beta1, resulting in potential information disclosure.

## Affected

- `vaadin >= 10.0.0, < 10.0.23`
- `vaadin >= 11.0.0, < 14.10.1`
- `vaadin >= 15.0.0, <= 22.0.28`
- `vaadin >= 23.0.0, < 23.3.13`
- `vaadin >= 24.0.0, < 24.0.6`
- `vaadin = 24.1.0`

## Remediation

Upgrade past the affected range:

- `vaadin 24.0.6`
