Regular Expression Denial of Service Vulnerability in iTop ITSM Tool from Combodo
CVE-2025-24026
What is CVE-2025-24026?
iTop is a web-based IT Service Management tool that has been identified to be vulnerable to a Regular Expression Denial of Service (ReDoS) attack in versions prior to 3.2.1. This vulnerability could potentially disrupt the iTop server under specific circumstances. However, users can apply a workaround by defining the app_root_url in their configuration file, effectively preventing possible exploitation of this ReDoS. The recommended version for users to upgrade to is 3.2.1, which mitigates this risk by not utilizing the affected variable in its regular expression.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
iTop < 3.2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
