CVE-2025-30151: Shopware allows Denial Of Service via password length
Impact
It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API.
Patches Update to Shopware 6.6.10.3 or 6.5.8.17
Workarounds For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
Other sources
Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30151?
CVE-2025-30151 has a high severity due to its potential to cause Denial of Service through long password inputs in Storefront forms.
How do I fix CVE-2025-30151?
To fix CVE-2025-30151, update your Shopware to version 6.6.10.3, 6.5.8.17, or apply corresponding security measures for older versions of 6.4.
What versions of Shopware are affected by CVE-2025-30151?
CVE-2025-30151 affects Shopware versions prior to 6.6.10.3 and 6.5.8.17, along with certain older versions of 6.4.
What impact does CVE-2025-30151 have on my Shopware application?
CVE-2025-30151 can lead to Denial of Service, potentially disrupting service availability for users.
Is there a known fix for CVE-2025-30151 in previous versions of Shopware?
Yes, corresponding security measures are available for older versions of Shopware 6.4 to mitigate CVE-2025-30151.