CVE-2025-35432: CISA Thorium does not rate limit account verification email messages
CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker can send unlimited messages to a user who is pending verification. Fixed in 1.1.1 by adding a rate limit set by default to 10 minutes.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-35432?
CVE-2025-35432 is classified as a medium severity vulnerability due to its potential for abuse through excessive email requests.
How do I fix CVE-2025-35432?
To fix CVE-2025-35432, update CISA Thorium to version 1.1.1 or later, which includes a rate limit feature.
Who is affected by CVE-2025-35432?
Users of CISA Thorium versions before 1.1.1 are affected by CVE-2025-35432.
What can an attacker do with CVE-2025-35432?
An attacker can exploit CVE-2025-35432 to send an unlimited number of account verification email messages, potentially causing denial of service.
When was CVE-2025-35432 reported?
CVE-2025-35432 was reported in 2025, highlighting a vulnerability in the CISA Thorium email verification process.