Cache-Write Performance Degradation in Ehcache 3.x by IBM
CVE-2025-2529

2.9LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
15 October 2025

What is CVE-2025-2529?

Applications utilizing Ehcache 3.x are susceptible to performance issues due to inadequate handling of cache keys from untrusted external sources. If keys are processed without proper filtering or salting, it can lead to significantly impaired cache-write operations, ultimately affecting the overall application performance. Developers must ensure robust validation and sanitization of these keys to mitigate the risk associated with this vulnerability.

Affected Version(s)

Terracotta 10.15.0 <= 10.15.0 IF23

Terracotta 11.1.0 <= 11.1.0 IF5

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-2529 : Cache-Write Performance Degradation in Ehcache 3.x by IBM