---
id: CVE-2025-20384
title: >-
  In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and
  Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and
  9.3.2411.117.125, an unauthenticated attacker can inject American National
  Standards Institute (…
summary: >-
  In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and
  Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and
  9.3.2411.117.125, an unauthenticated attacker can inject American National
  Standards Institute (…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-117
vendor: splunk
product: splunk
affected:
  - 'splunk >= 9.2.0, < 9.2.10'
  - 'splunk >= 9.3.0, < 9.3.8'
  - 'splunk >= 9.4.0, < 9.4.6'
  - splunk = 10.0.0
  - 'splunk_cloud_platform >= 9.3.2411, < 9.3.2411.117'
  - 'splunk_cloud_platform >= 10.0.2503, < 10.0.2503.6'
  - 'splunk_cloud_platform >= 10.1.2507, < 10.1.2507.4'
patched:
  - splunk 9.4.6
  - splunk_cloud_platform 10.1.2507.4
published: '2025-12-03'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-20384'
references:
  - url: 'https://advisory.splunk.com/advisories/SVD-2025-1203'
    label: psirt@cisco.com
tags:
  - nvd
  - exploit-available
epss: 0.00385
epssPercentile: 0.29877
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Axselll/CVE-2025-20384'
  checkedAt: '2026-09-25T23:21:52.266Z'
exploitAvailable: true
ingestedAt: '2026-09-25T23:21:16.869Z'
---

## Overview

In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files due to improper validation at the /en-US/static/ web endpoint. This may allow them to poison, forge, or obfuscate sensitive log data through specially crafted HTTP requests, potentially impacting log integrity and detection capabilities.

## Affected

- `splunk >= 9.2.0, < 9.2.10`
- `splunk >= 9.3.0, < 9.3.8`
- `splunk >= 9.4.0, < 9.4.6`
- `splunk = 10.0.0`
- `splunk_cloud_platform >= 9.3.2411, < 9.3.2411.117`
- `splunk_cloud_platform >= 10.0.2503, < 10.0.2503.6`
- `splunk_cloud_platform >= 10.1.2507, < 10.1.2507.4`

## Remediation

Upgrade past the affected range:

- `splunk 9.4.6`
- `splunk_cloud_platform 10.1.2507.4`
