CVE Vulnerabilities

CVE-2025-43796

Uncontrolled Resource Consumption

Published: Sep 12, 2025 | Modified: Dec 16, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing queries that return a large number of objects.

Weakness

The product does not properly control the allocation and maintenance of a limited resource.

Affected Software

NameVendorStart VersionEnd Version
Digital_experience_platformLiferay2023.Q3.0 (including)2023.Q3.5 (excluding)
Digital_experience_platformLiferay7.3 (including)7.3 (including)
Digital_experience_platformLiferay7.3-fix_pack_1 (including)7.3-fix_pack_1 (including)
Digital_experience_platformLiferay7.3-fix_pack_2 (including)7.3-fix_pack_2 (including)
Digital_experience_platformLiferay7.3-service_pack_1 (including)7.3-service_pack_1 (including)
Digital_experience_platformLiferay7.3-service_pack_2 (including)7.3-service_pack_2 (including)
Digital_experience_platformLiferay7.3-service_pack_3 (including)7.3-service_pack_3 (including)
Digital_experience_platformLiferay7.3-update1 (including)7.3-update1 (including)
Digital_experience_platformLiferay7.3-update10 (including)7.3-update10 (including)
Digital_experience_platformLiferay7.3-update11 (including)7.3-update11 (including)
Digital_experience_platformLiferay7.3-update12 (including)7.3-update12 (including)
Digital_experience_platformLiferay7.3-update13 (including)7.3-update13 (including)
Digital_experience_platformLiferay7.3-update14 (including)7.3-update14 (including)
Digital_experience_platformLiferay7.3-update15 (including)7.3-update15 (including)
Digital_experience_platformLiferay7.3-update16 (including)7.3-update16 (including)
Digital_experience_platformLiferay7.3-update17 (including)7.3-update17 (including)
Digital_experience_platformLiferay7.3-update18 (including)7.3-update18 (including)
Digital_experience_platformLiferay7.3-update19 (including)7.3-update19 (including)
Digital_experience_platformLiferay7.3-update2 (including)7.3-update2 (including)
Digital_experience_platformLiferay7.3-update20 (including)7.3-update20 (including)
Digital_experience_platformLiferay7.3-update21 (including)7.3-update21 (including)
Digital_experience_platformLiferay7.3-update22 (including)7.3-update22 (including)
Digital_experience_platformLiferay7.3-update23 (including)7.3-update23 (including)
Digital_experience_platformLiferay7.3-update24 (including)7.3-update24 (including)
Digital_experience_platformLiferay7.3-update25 (including)7.3-update25 (including)
Digital_experience_platformLiferay7.3-update26 (including)7.3-update26 (including)
Digital_experience_platformLiferay7.3-update27 (including)7.3-update27 (including)
Digital_experience_platformLiferay7.3-update28 (including)7.3-update28 (including)
Digital_experience_platformLiferay7.3-update29 (including)7.3-update29 (including)
Digital_experience_platformLiferay7.3-update3 (including)7.3-update3 (including)
Digital_experience_platformLiferay7.3-update30 (including)7.3-update30 (including)
Digital_experience_platformLiferay7.3-update31 (including)7.3-update31 (including)
Digital_experience_platformLiferay7.3-update32 (including)7.3-update32 (including)
Digital_experience_platformLiferay7.3-update33 (including)7.3-update33 (including)
Digital_experience_platformLiferay7.3-update34 (including)7.3-update34 (including)
Digital_experience_platformLiferay7.3-update35 (including)7.3-update35 (including)
Digital_experience_platformLiferay7.3-update4 (including)7.3-update4 (including)
Digital_experience_platformLiferay7.3-update5 (including)7.3-update5 (including)
Digital_experience_platformLiferay7.3-update6 (including)7.3-update6 (including)
Digital_experience_platformLiferay7.3-update7 (including)7.3-update7 (including)
Digital_experience_platformLiferay7.3-update8 (including)7.3-update8 (including)
Digital_experience_platformLiferay7.3-update9 (including)7.3-update9 (including)
Digital_experience_platformLiferay7.4 (including)7.4 (including)
Digital_experience_platformLiferay7.4-update1 (including)7.4-update1 (including)
Digital_experience_platformLiferay7.4-update10 (including)7.4-update10 (including)
Digital_experience_platformLiferay7.4-update11 (including)7.4-update11 (including)
Digital_experience_platformLiferay7.4-update12 (including)7.4-update12 (including)
Digital_experience_platformLiferay7.4-update13 (including)7.4-update13 (including)
Digital_experience_platformLiferay7.4-update14 (including)7.4-update14 (including)
Digital_experience_platformLiferay7.4-update15 (including)7.4-update15 (including)
Digital_experience_platformLiferay7.4-update16 (including)7.4-update16 (including)
Digital_experience_platformLiferay7.4-update17 (including)7.4-update17 (including)
Digital_experience_platformLiferay7.4-update18 (including)7.4-update18 (including)
Digital_experience_platformLiferay7.4-update19 (including)7.4-update19 (including)
Digital_experience_platformLiferay7.4-update2 (including)7.4-update2 (including)
Digital_experience_platformLiferay7.4-update20 (including)7.4-update20 (including)
Digital_experience_platformLiferay7.4-update21 (including)7.4-update21 (including)
Digital_experience_platformLiferay7.4-update22 (including)7.4-update22 (including)
Digital_experience_platformLiferay7.4-update23 (including)7.4-update23 (including)
Digital_experience_platformLiferay7.4-update24 (including)7.4-update24 (including)
Digital_experience_platformLiferay7.4-update25 (including)7.4-update25 (including)
Digital_experience_platformLiferay7.4-update26 (including)7.4-update26 (including)
Digital_experience_platformLiferay7.4-update27 (including)7.4-update27 (including)
Digital_experience_platformLiferay7.4-update28 (including)7.4-update28 (including)
Digital_experience_platformLiferay7.4-update29 (including)7.4-update29 (including)
Digital_experience_platformLiferay7.4-update3 (including)7.4-update3 (including)
Digital_experience_platformLiferay7.4-update30 (including)7.4-update30 (including)
Digital_experience_platformLiferay7.4-update31 (including)7.4-update31 (including)
Digital_experience_platformLiferay7.4-update32 (including)7.4-update32 (including)
Digital_experience_platformLiferay7.4-update33 (including)7.4-update33 (including)
Digital_experience_platformLiferay7.4-update34 (including)7.4-update34 (including)
Digital_experience_platformLiferay7.4-update35 (including)7.4-update35 (including)
Digital_experience_platformLiferay7.4-update36 (including)7.4-update36 (including)
Digital_experience_platformLiferay7.4-update37 (including)7.4-update37 (including)
Digital_experience_platformLiferay7.4-update38 (including)7.4-update38 (including)
Digital_experience_platformLiferay7.4-update39 (including)7.4-update39 (including)
Digital_experience_platformLiferay7.4-update4 (including)7.4-update4 (including)
Digital_experience_platformLiferay7.4-update40 (including)7.4-update40 (including)
Digital_experience_platformLiferay7.4-update41 (including)7.4-update41 (including)
Digital_experience_platformLiferay7.4-update42 (including)7.4-update42 (including)
Digital_experience_platformLiferay7.4-update43 (including)7.4-update43 (including)
Digital_experience_platformLiferay7.4-update44 (including)7.4-update44 (including)
Digital_experience_platformLiferay7.4-update45 (including)7.4-update45 (including)
Digital_experience_platformLiferay7.4-update46 (including)7.4-update46 (including)
Digital_experience_platformLiferay7.4-update47 (including)7.4-update47 (including)
Digital_experience_platformLiferay7.4-update48 (including)7.4-update48 (including)
Digital_experience_platformLiferay7.4-update49 (including)7.4-update49 (including)
Digital_experience_platformLiferay7.4-update5 (including)7.4-update5 (including)
Digital_experience_platformLiferay7.4-update50 (including)7.4-update50 (including)
Digital_experience_platformLiferay7.4-update51 (including)7.4-update51 (including)
Digital_experience_platformLiferay7.4-update52 (including)7.4-update52 (including)
Digital_experience_platformLiferay7.4-update53 (including)7.4-update53 (including)
Digital_experience_platformLiferay7.4-update54 (including)7.4-update54 (including)
Digital_experience_platformLiferay7.4-update55 (including)7.4-update55 (including)
Digital_experience_platformLiferay7.4-update56 (including)7.4-update56 (including)
Digital_experience_platformLiferay7.4-update57 (including)7.4-update57 (including)
Digital_experience_platformLiferay7.4-update58 (including)7.4-update58 (including)
Digital_experience_platformLiferay7.4-update59 (including)7.4-update59 (including)
Digital_experience_platformLiferay7.4-update6 (including)7.4-update6 (including)
Digital_experience_platformLiferay7.4-update60 (including)7.4-update60 (including)
Digital_experience_platformLiferay7.4-update61 (including)7.4-update61 (including)
Digital_experience_platformLiferay7.4-update62 (including)7.4-update62 (including)
Digital_experience_platformLiferay7.4-update63 (including)7.4-update63 (including)
Digital_experience_platformLiferay7.4-update64 (including)7.4-update64 (including)
Digital_experience_platformLiferay7.4-update65 (including)7.4-update65 (including)
Digital_experience_platformLiferay7.4-update66 (including)7.4-update66 (including)
Digital_experience_platformLiferay7.4-update67 (including)7.4-update67 (including)
Digital_experience_platformLiferay7.4-update68 (including)7.4-update68 (including)
Digital_experience_platformLiferay7.4-update69 (including)7.4-update69 (including)
Digital_experience_platformLiferay7.4-update7 (including)7.4-update7 (including)
Digital_experience_platformLiferay7.4-update70 (including)7.4-update70 (including)
Digital_experience_platformLiferay7.4-update71 (including)7.4-update71 (including)
Digital_experience_platformLiferay7.4-update72 (including)7.4-update72 (including)
Digital_experience_platformLiferay7.4-update73 (including)7.4-update73 (including)
Digital_experience_platformLiferay7.4-update74 (including)7.4-update74 (including)
Digital_experience_platformLiferay7.4-update75 (including)7.4-update75 (including)
Digital_experience_platformLiferay7.4-update76 (including)7.4-update76 (including)
Digital_experience_platformLiferay7.4-update77 (including)7.4-update77 (including)
Digital_experience_platformLiferay7.4-update78 (including)7.4-update78 (including)
Digital_experience_platformLiferay7.4-update79 (including)7.4-update79 (including)
Digital_experience_platformLiferay7.4-update8 (including)7.4-update8 (including)
Digital_experience_platformLiferay7.4-update80 (including)7.4-update80 (including)
Digital_experience_platformLiferay7.4-update81 (including)7.4-update81 (including)
Digital_experience_platformLiferay7.4-update82 (including)7.4-update82 (including)
Digital_experience_platformLiferay7.4-update83 (including)7.4-update83 (including)
Digital_experience_platformLiferay7.4-update84 (including)7.4-update84 (including)
Digital_experience_platformLiferay7.4-update85 (including)7.4-update85 (including)
Digital_experience_platformLiferay7.4-update86 (including)7.4-update86 (including)
Digital_experience_platformLiferay7.4-update87 (including)7.4-update87 (including)
Digital_experience_platformLiferay7.4-update88 (including)7.4-update88 (including)
Digital_experience_platformLiferay7.4-update89 (including)7.4-update89 (including)
Digital_experience_platformLiferay7.4-update9 (including)7.4-update9 (including)
Digital_experience_platformLiferay7.4-update90 (including)7.4-update90 (including)
Digital_experience_platformLiferay7.4-update91 (including)7.4-update91 (including)
Digital_experience_platformLiferay7.4-update92 (including)7.4-update92 (including)
Liferay_portalLiferay7.4.0 (including)7.4.3.102 (excluding)

Potential Mitigations

  • Mitigation of resource exhaustion attacks requires that the target system either:

  • The first of these solutions is an issue in itself though, since it may allow attackers to prevent the use of the system by a particular valid user. If the attacker impersonates the valid user, they may be able to prevent the user from accessing the server in question.

  • The second solution is simply difficult to effectively institute – and even when properly done, it does not provide a full solution. It simply makes the attack require more resources on the part of the attacker.

References