icon

We found results for “

CVE-2025-66473

Good to know:

icon
icon

Date: December 10, 2025

XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 through 17.6.0 contain a REST API which doesn't enforce any limits for the number of items that can be requested in a single request at the moment. Depending on the number of pages in the wiki and the memory configuration, this can lead to slowness and unavailability of the wiki. As an example, the /rest/wikis/xwiki/spaces resource returns all spaces on the wiki by default, which are basically all pages. This issue is fixed in versions 17.4.4 and 16.10.11.

Severity Score

Severity Score

Weakness Type (CWE)

Allocation of Resources Without Limits or Throttling

CWE-770

Top Fix

icon

Upgrade Version

Upgrade to version org.xwiki.platform:xwiki-platform-rest-server:16.10.11;org.xwiki.platform:xwiki-platform-rest-server:17.4.4;org.xwiki.platform:xwiki-platform-rest-server:17.7.0-rc-1;https://github.com/xwiki/xwiki-platform.git - xwiki-platform-16.10.11;https://github.com/xwiki/xwiki-platform.git - xwiki-platform-17.4.4;https://github.com/xwiki/xwiki-platform.git - xwiki-platform-17.7.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us