GHSA-9gfh-4fwj-w3rj

Suggest an improvement
Source
https://github.com/advisories/GHSA-9gfh-4fwj-w3rj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-9gfh-4fwj-w3rj/GHSA-9gfh-4fwj-w3rj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9gfh-4fwj-w3rj
Aliases
Published
2025-09-04T15:54:58Z
Modified
2026-09-10T03:50:28Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/S:N/AU:N/R:U/V:D/RE:L/U:Green CVSS Calculator
Summary
Vaadin Framework possible file bypass via upload validation on the server-side
Details

Description

When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Users of affected versions should apply the upgrade to a more recent Vaadin version.

Database specific
{
    "cwe_ids":  [
        "CWE-20",
        "CWE-434"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-09-04T15:54:58Z",
    "nvd_published_at":  "2025-09-04T10:42:34Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / com.vaadin:vaadin-server

Package

Name
com.vaadin:vaadin-server
View open source insights on deps.dev
Purl
pkg:maven/com.vaadin/vaadin-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
7.7.48

Affected versions

7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.1.0.beta1
7.1.0
7.1.1
7.1.2
7.1.3
7.1.4
7.1.5
7.1.6
7.1.7
7.1.8
7.1.9
7.1.10
7.1.11
7.1.12
7.1.13
7.1.14
7.1.15
7.2.0.beta1
7.2.0
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.6
7.2.7
7.3.0.alpha1
7.3.0.alpha2
7.3.0.alpha3
7.3.0.beta1
7.3.0.rc1
7.3.0
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.3.10
7.4.0.alpha1
7.4.0.alpha2
7.4.0.alpha3
7.4.0.alpha4
7.4.0.alpha5
7.4.0.alpha6
7.4.0.alpha7
7.4.0.alpha8
7.4.0.alpha9
7.4.0.alpha10
7.4.0.alpha11
7.4.0.alpha12
7.4.0.alpha13
7.4.0.alpha14
7.4.0.beta1
7.4.0.beta2
7.4.0.beta3
7.4.0.rc1
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.4.8
7.5.0.alpha1
7.5.0.beta1
7.5.0.beta2
7.5.0.beta3
7.5.0.rc1
7.5.0.rc2
7.5.0
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
7.5.6
7.5.7
7.5.8
7.5.9
7.5.10
7.6.0.alpha1
7.6.0.alpha2
7.6.0
7.6.1
7.6.2
7.6.3
7.6.4
7.6.5
7.6.6
7.6.7
7.6.8
7.7.0
7.7.1
7.7.2
7.7.3
7.7.4
7.7.5
7.7.6
7.7.7
7.7.8
7.7.9
7.7.10
7.7.11
7.7.12
7.7.13
7.7.14
7.7.15
7.7.16
7.7.17
7.7.23
7.7.24
7.7.25
7.7.26
7.7.27
7.7.28
7.7.29
7.7.30
7.7.31
7.7.32
7.7.33
7.7.34
7.7.35
7.7.36
7.7.37
7.7.38
7.7.39
7.7.40
7.7.41
7.7.42
7.7.43
7.7.44
7.7.45
7.7.46
7.7.47

Database specific

last_known_affected_version_range
"<= 7.7.47"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-9gfh-4fwj-w3rj/GHSA-9gfh-4fwj-w3rj.json"

Maven / com.vaadin:vaadin-server

Package

Name
com.vaadin:vaadin-server
View open source insights on deps.dev
Purl
pkg:maven/com.vaadin/vaadin-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.0.0
Fixed
8.28.2

Affected versions

8.*
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.0.7
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.1.8
8.2.0
8.2.1
8.3.0
8.3.1
8.3.2
8.3.3
8.4.0
8.4.1
8.4.2
8.4.3
8.4.4
8.4.5
8.5.0
8.5.1
8.5.2
8.6.0
8.6.1
8.6.2
8.6.3
8.6.4
8.7.0.beta1
8.7.0
8.7.1
8.7.2
8.8.0
8.8.1
8.8.2
8.8.3
8.8.4
8.8.5
8.8.6
8.9.0
8.9.1
8.9.2
8.9.3
8.9.4
8.10.0
8.10.1
8.10.2
8.10.3
8.10.4
8.10.5
8.11.0
8.11.1
8.11.2
8.11.3
8.12.0
8.12.1
8.12.2
8.12.3
8.12.4
8.13.0
8.13.1
8.13.2
8.13.3
8.14.0
8.14.1
8.14.2
8.14.3
8.14.4
8.14.5
8.15.0
8.15.1
8.15.2
8.16.0
8.16.1
8.17.0
8.18.0
8.19.0
8.20.0
8.20.1
8.20.2
8.20.3
8.21.0
8.22.0
8.23.0
8.24.0
8.25.0
8.25.1
8.25.2
8.26.0
8.27.0
8.27.1
8.27.2
8.27.3
8.27.4
8.27.5
8.27.6
8.27.7
8.28.0
8.28.1

Database specific

last_known_affected_version_range
"<= 8.28.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-9gfh-4fwj-w3rj/GHSA-9gfh-4fwj-w3rj.json"