Regular Expression Denial of Service Vulnerability in iTop ITSM Tool from Combodo
CVE-2025-24026
5.3MEDIUM
What is CVE-2025-24026?
iTop is a web-based IT Service Management tool that has been identified to be vulnerable to a Regular Expression Denial of Service (ReDoS) attack in versions prior to 3.2.1. This vulnerability could potentially disrupt the iTop server under specific circumstances. However, users can apply a workaround by defining the app_root_url in their configuration file, effectively preventing possible exploitation of this ReDoS. The recommended version for users to upgrade to is 3.2.1, which mitigates this risk by not utilizing the affected variable in its regular expression.
Affected Version(s)
iTop < 3.2.1