CVE-2025-32952
Analyzed Analyzed - Analysis Complete

BaseFortify

Vulnerability report for CVE-2025-32952, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2025-04-22

Last updated on: 2025-12-31

Assigner: GitHub, Inc.

Description

Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the local file storage implementation does not restrict the size of uploaded files. An attacker could exploit this by uploading excessively large files, potentially causing the server to run out of space and return HTTP 500 error, resulting in a denial of service. This issue has been patched in versions 1.6.2 and 2.4.0. A workaround is provided on the Jmix documentation website.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2025-04-22
Last Modified
2025-12-31
Generated
2026-07-27
AI Q&A
2025-04-23
EPSS Evaluated
2026-07-26
NVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
haulmont cuba_platform From 6.2.0 (inc) to 7.2.23 (exc)
haulmont cuba_rest_api From 7.1.1 (inc) to 7.2.7 (exc)
haulmont jmix_framework From 1.0.0 (inc) to 1.6.2 (exc)
haulmont jmix_framework From 2.0.0 (inc) to 2.4.0 (exc)
haulmont jpa_web_api From 1.0.0 (inc) to 1.1.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in Jmix’s local file storage implementation. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, there is no restriction on the size of uploaded files. An attacker can exploit this by uploading excessively large files that may exhaust the server's disk space, potentially triggering HTTP 500 errors and leading to a denial of service. The issue has been fixed in versions 1.6.2 and 2.4.0, with a workaround available on the Jmix documentation website. [1]

Impact Analysis

If you are using an affected Jmix version, an attacker could exploit this vulnerability by uploading very large files without restrictions, which might exhaust available disk space on your server. This can cause the server to become unresponsive due to HTTP 500 errors, resulting in a denial of service and disruption of service availability. [1]

Mitigation Strategies

The immediate steps are to upgrade to the patched versions (1.6.2 for the 1.x branch or 2.4.0 for the 2.x branch). Alternatively, you can follow the workaround provided on the Jmix documentation website. [1, 2]

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-32952. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart