CVE-2025-30151

Source
https://cve.org/CVERecord?id=CVE-2025-30151
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30151.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-30151
Aliases
Published
2025-04-08T13:46:30.629Z
Modified
2026-08-12T03:51:39.072257409Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Shopware allows Denial Of Service via password length
Details

Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

Database specific
{
    "cwe_ids": [
        "CWE-20"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30151.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/shopware/shopware

Affected ranges

Type
GIT
Repo
https://github.com/shopware/shopware
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:shopware:shopware:6.7.0.0:rc1:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "6.5.8.17"
        },
        {
            "introduced": "6.6.0.0"
        },
        {
            "fixed": "6.6.10.3"
        },
        {
            "introduced": "6.7.0.0-rc1"
        },
        {
            "last_affected": "6.7.0.0-rc1"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

6.*
6.7.0.0-rc1
v6.*
v6.5.8.15
v6.5.8.16
v6.5.8.3
v6.5.8.8
v6.5.8.9
v6.6.10.0
v6.6.10.1
v6.6.10.2
v6.7.0.0-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30151.json"