---
id: CVE-2025-14516
title: A vulnerability was found in Yalantis uCrop 2.2.11
summary: >-
  A vulnerability was found in Yalantis uCrop 2.2.11. Affected by this issue is
  the function downloadFile of the file
  com.yalantis.ucrop.task.BitmapLoadTask.java of the component URL Handler.
  Performing manipulation results in server-side …
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-918
vendor: yalantis
product: ucrop
affected:
  - ucrop = 2.2.11
published: '2025-12-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14516'
references:
  - url: >-
      https://mesquite-dream-86b.notion.site/uCrop-Library-SSRF-and-Intent-Spoofing-2b8512562197804dae69edf96b942446
    label: cna@vuldb.com
  - url: >-
      https://mesquite-dream-86b.notion.site/uCrop-Library-SSRF-and-Intent-Spoofing-2b8512562197804dae69edf96b942446?pvs=25#039fe30a92dc4ed88c9b03f85418e92e
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.335854'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.335854'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.702810'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00461
epssPercentile: 0.37935
ingestedAt: '2026-10-08T10:28:24.912Z'
---

## Overview

A vulnerability was found in Yalantis uCrop 2.2.11. Affected by this issue is the function downloadFile of the file com.yalantis.ucrop.task.BitmapLoadTask.java of the component URL Handler. Performing manipulation results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `ucrop = 2.2.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
