CVE Vulnerabilities

CVE-2025-26516

Asymmetric Resource Consumption (Amplification)

Published: Sep 19, 2025 | Modified: Sep 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Denial of Service vulnerability. Successful exploit could allow an unauthenticated attacker to cause a Denial of Service on the Admin node.

Weakness

The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary’s influence is “asymmetric.”

Affected Software

Name Vendor Start Version End Version
Storagegrid Netapp * 11.8.0.15 (excluding)
Storagegrid Netapp 11.9.0 (including) 11.9.0.8 (excluding)

Potential Mitigations

References