CVE-2025-53645 Information
Description
Zimbra Collaboration Suite (ZCS) before 9.0.0 Patch 46 10.0.x before 10.0.15 and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due to improper handling of excessive comma-separated path segments in both the Webmail interface and the Admin Console. An unauthenticated remote attacker can send specially crafted GET requests that trigger redundant processing and inflated responses. This leads to uncontrolled resource consumption resulting in denial of service.
Reference
https://wiki.zimbra.com/wiki/Security_Center https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.15#Security_Fixes https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.9#Security_Fixes https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P46#Security_Fixes https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories
Related CNNVD
CNNVD-202507-1343 (Published: 2025-07-09)
Share on: