GHSA-f3hf-r62c-mfrj

Suggest an improvement
Source
https://github.com/advisories/GHSA-f3hf-r62c-mfrj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-f3hf-r62c-mfrj/GHSA-f3hf-r62c-mfrj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f3hf-r62c-mfrj
Aliases
  • CVE-2025-43796
Published
2025-09-12T21:32:14Z
Modified
2025-09-15T14:12:20.158555Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Liferay Portal: Missing Rate Limiting in GraphQL Endpoint Enables Resource Exhaustion Attack
Details

Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing queries that return a large number of objects.

Database specific
{
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-400"
    ],
    "github_reviewed_at": "2025-09-15T13:46:24Z",
    "nvd_published_at": "2025-09-12T20:15:42Z"
}
References

Affected packages

Maven / com.liferay:com.liferay.portal.vulcan.api

Package

Name
com.liferay:com.liferay.portal.vulcan.api
View open source insights on deps.dev
Purl
pkg:maven/com.liferay/com.liferay.portal.vulcan.api

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.0.2
Fixed
40.2.0

Affected versions

8.*

8.1.0
8.1.1
8.2.0
8.3.0
8.3.1
8.3.2
8.3.3

9.*

9.0.0
9.1.0
9.2.0
9.2.1
9.3.0
9.3.1
9.4.0
9.5.0
9.5.1
9.6.0
9.6.1
9.7.0
9.7.1
9.8.0
9.8.1
9.8.2
9.8.3
9.9.0
9.10.0
9.11.0

10.*

10.0.0
10.0.1

11.*

11.0.0
11.0.1
11.0.2

12.*

12.0.0

13.*

13.0.0
13.0.1

14.*

14.0.0

15.*

15.0.0
15.1.0
15.1.1

16.*

16.0.0

17.*

17.0.0

18.*

18.0.0

19.*

19.0.0

20.*

20.0.0

21.*

21.0.0

22.*

22.0.0
22.0.1
22.0.2
22.0.3
22.0.4
22.0.5

23.*

23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.1.0
23.1.1
23.1.2

24.*

24.0.0
24.0.1
24.1.0
24.1.1
24.1.2
24.1.3
24.1.4
24.1.5
24.2.0
24.2.1
24.2.2

25.*

25.0.0
25.1.0
25.2.0

26.*

26.0.0
26.1.0

27.*

27.0.0

28.*

28.0.0

29.*

29.0.0
29.0.1

30.*

30.0.0
30.0.1

31.*

31.0.0
31.1.0
31.1.1
31.1.2
31.2.0
31.2.1
31.2.2
31.2.3

32.*

32.0.0

33.*

33.0.0
33.0.1

34.*

34.0.0

35.*

35.0.0
35.1.0
35.1.1
35.2.0

36.*

36.0.0
36.1.0

37.*

37.0.0

38.*

38.0.0
38.1.0

39.*

39.0.0

40.*

40.0.0
40.1.0

Maven / com.liferay:com.liferay.portal.vulcan.impl

Package

Name
com.liferay:com.liferay.portal.vulcan.impl
View open source insights on deps.dev
Purl
pkg:maven/com.liferay/com.liferay.portal.vulcan.impl

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.7
Fixed
5.0.105

Affected versions

5.*

5.0.7
5.0.8
5.0.9
5.0.10
5.0.11
5.0.12
5.0.13
5.0.14
5.0.15
5.0.16
5.0.17
5.0.18
5.0.19
5.0.20
5.0.21
5.0.22
5.0.23
5.0.24
5.0.25
5.0.26
5.0.27
5.0.28
5.0.29
5.0.30
5.0.31
5.0.32
5.0.33
5.0.34
5.0.35
5.0.36
5.0.37
5.0.38
5.0.39
5.0.40
5.0.41
5.0.42
5.0.43
5.0.44
5.0.45
5.0.46
5.0.47
5.0.48
5.0.49
5.0.50
5.0.51
5.0.52
5.0.53
5.0.54
5.0.55
5.0.56
5.0.57
5.0.58
5.0.59
5.0.60
5.0.61
5.0.62
5.0.63
5.0.64
5.0.65
5.0.66
5.0.67
5.0.68
5.0.69
5.0.70
5.0.71
5.0.72
5.0.73
5.0.74
5.0.75
5.0.76
5.0.77
5.0.78
5.0.79
5.0.80
5.0.81
5.0.82
5.0.83
5.0.84
5.0.85
5.0.86
5.0.87
5.0.88
5.0.89
5.0.90
5.0.91
5.0.92
5.0.93
5.0.94
5.0.95
5.0.96
5.0.97
5.0.98
5.0.99
5.0.100
5.0.101
5.0.102
5.0.103
5.0.104