CVE-2025-66487
Received Received - Intake
Rate Limiting Bypass in IBM Aspera Shares Causes Email Flooding

Publication date: 2026-04-01

Last updated on: 2026-04-03

Assigner: IBM Corporation

Description
IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in email flooding or a denial of service.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-01
Last Modified
2026-04-03
Generated
2026-06-16
AI Q&A
2026-04-02
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
ibm aspera_shares From 1.9.9 (inc) to 1.11.1 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

IBM Aspera Shares versions 1.9.9 through 1.11.0 have a vulnerability where the system does not properly limit how often an authenticated user can send emails.

Because of this, a user could send a large number of emails in a short period, potentially overwhelming the email system.

Impact Analysis

This vulnerability could lead to email flooding, where the email system is overwhelmed by a high volume of emails sent by an authenticated user.

Such flooding could cause a denial of service, making the email functionality unavailable or degraded for legitimate users.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-66487. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart