CVE-2025-32952
Analyzed Analyzed - Analysis Complete
BaseFortify

Publication date: 2025-04-22

Last updated on: 2025-12-31

Assigner: GitHub, Inc.

Description
Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the local file storage implementation does not restrict the size of uploaded files. An attacker could exploit this by uploading excessively large files, potentially causing the server to run out of space and return HTTP 500 error, resulting in a denial of service. This issue has been patched in versions 1.6.2 and 2.4.0. A workaround is provided on the Jmix documentation website.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-04-22
Last Modified
2025-12-31
Generated
2026-06-24
AI Q&A
2025-04-23
EPSS Evaluated
2026-06-23
NVD
Affected Vendors & Products
Showing 5 associated CPEs
Vendor Product Version / Range
haulmont cuba_platform From 6.2.0 (inc) to 7.2.23 (exc)
haulmont cuba_rest_api From 7.1.1 (inc) to 7.2.7 (exc)
haulmont jmix_framework From 1.0.0 (inc) to 1.6.2 (exc)
haulmont jmix_framework From 2.0.0 (inc) to 2.4.0 (exc)
haulmont jpa_web_api From 1.0.0 (inc) to 1.1.1 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in Jmix’s local file storage implementation. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, there is no restriction on the size of uploaded files. An attacker can exploit this by uploading excessively large files that may exhaust the server's disk space, potentially triggering HTTP 500 errors and leading to a denial of service. The issue has been fixed in versions 1.6.2 and 2.4.0, with a workaround available on the Jmix documentation website. [1]

Impact Analysis

If you are using an affected Jmix version, an attacker could exploit this vulnerability by uploading very large files without restrictions, which might exhaust available disk space on your server. This can cause the server to become unresponsive due to HTTP 500 errors, resulting in a denial of service and disruption of service availability. [1]

Mitigation Strategies

The immediate steps are to upgrade to the patched versions (1.6.2 for the 1.x branch or 2.4.0 for the 2.x branch). Alternatively, you can follow the workaround provided on the Jmix documentation website. [1, 2]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-32952. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart