CVE-2025-58582Medium· 5.3▾ SunlitIf a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged.
enterprise_analyticsRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-58578Low· 3.8A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request
CVE-2025-58583Medium· 5.3The application provides access to a login protected H2 database for caching purposes
CVE-2025-58581Medium· 4.3When an error occurs in the application a full stacktrace is provided to the user
CVE-2025-58580Medium· 6.5An API endpoint allows arbitrary log entries to be created via POST request
CVE-2025-59459Medium· 5.5An attacker that gains SSH access to an unprivileged account may be able to disrupt services (including SSH), causing persistent loss of availability.
CVE-2025-59463Medium· 4.3An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.