CVE Vulnerabilities

CVE-2026-25957

Improper Handling of Exceptional Conditions

Published: Feb 09, 2026 | Modified: Feb 24, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. This vulnerability is fixed in 1.5.13 and 1.4.2.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

NameVendorStart VersionEnd Version
Cube.jsCube1.1.17 (including)1.4.2 (excluding)
Cube.jsCube1.5.0 (including)1.5.13 (excluding)

References