PT-2025-28942 · Zimbra · Zimbra Collaboration Suite

CVE-2025-53645

·

Published

2025-06-18

·

Updated

2025-12-23

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Zimbra Collaboration Suite versions prior to 9.0.0 Patch 46 Zimbra Collaboration Suite versions 10.0.x prior to 10.0.15 Zimbra Collaboration Suite versions 10.1.x prior to 10.1.9
Description: The software is susceptible to a denial of service condition caused by improper handling of excessive, comma-separated path segments in the Webmail interface and the Admin Console. An unauthenticated remote attacker can send specially crafted GET requests that trigger redundant processing and inflated responses, leading to uncontrolled resource consumption and denial of service.
Recommendations: Update to Zimbra Collaboration Suite version 9.0.0 Patch 46 or later. Update to Zimbra Collaboration Suite version 10.0.15 or later. Update to Zimbra Collaboration Suite version 10.1.9 or later.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16378
CVE-2025-53645

Affected Products

Zimbra Collaboration Suite