CVE-2025-62260: High severity Liferay portal vulnerability
Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing a request that returns a large number of objects.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62260?
CVE-2025-62260 is classified as a denial-of-service vulnerability that can be exploited by attackers.
How do I fix CVE-2025-62260?
To fix CVE-2025-62260, upgrade to the latest patched versions of Liferay Portal or Liferay DXP as specified by the vendor.
Which versions are affected by CVE-2025-62260?
CVE-2025-62260 affects Liferay Portal versions 7.4.0 through 7.4.3.99 and several versions of Liferay DXP, specifically 2023.Q3.1 through 2023.Q3.4.
What impact does CVE-2025-62260 have on my system?
The impact of CVE-2025-62260 is that remote attackers can exploit it to perform denial-of-service attacks, potentially disrupting service availability.
Is there a workaround for CVE-2025-62260?
There are no official workarounds for CVE-2025-62260; upgrading to the latest version is the recommended mitigation.