Skip to main content

CVE-2025-43816: CWE-401 Missing Release of Memory after Effective Lifetime in Liferay Portal

Medium
VulnerabilityCVE-2025-43816cvecve-2025-43816cwe-401
Published: Thu Sep 25 2025 (09/25/2025, 20:02:40 UTC)
Source: CVE Database V5
Vendor/Project: Liferay
Product: Portal

Description

A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows an attacker to cause server unavailability (denial of service) via repeatedly calling the API endpoint.

Technical Details

Data Version
5.1
Assigner Short Name
Liferay
Date Reserved
2025-04-17T10:55:35.684Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 68d5da079e21be37e937d058

Added to database: 9/26/2025, 12:10:47 AM

Last updated: 9/26/2025, 12:10:47 AM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats