CVE-2025-3986

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 27, 2025
Updated: Apr 29, 2025
CWE ID 1333
CWE ID 400

Summary

CVE-2025-3986 is a newly disclosed vulnerability affecting Apereo CAS 5.2.6. The issue lies within the file CasConfigurationMetadataServerController.java, where inefficient regular expression complexity can be triggered by manipulating the Name argument. This vulnerability poses a remote exploit risk and has already been made public. Despite early notification, the vendor has yet to provide a response.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share