Regular Expression Denial of Service Vulnerability in iTop ITSM Tool from Combodo
CVE-2025-24026

5.3MEDIUM

Key Information:

Vendor

Combodo

Status
Vendor
CVE Published:
14 May 2025

What is CVE-2025-24026?

iTop is a web-based IT Service Management tool that has been identified to be vulnerable to a Regular Expression Denial of Service (ReDoS) attack in versions prior to 3.2.1. This vulnerability could potentially disrupt the iTop server under specific circumstances. However, users can apply a workaround by defining the app_root_url in their configuration file, effectively preventing possible exploitation of this ReDoS. The recommended version for users to upgrade to is 3.2.1, which mitigates this risk by not utilizing the affected variable in its regular expression.

Affected Version(s)

iTop < 3.2.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.