Remote Code Execution Vulnerability in CISA Thorium Product
CVE-2025-35432
6.9MEDIUM
What is CVE-2025-35432?
CISA Thorium has a vulnerability that allows attackers to exploit the system by sending an unlimited number of account verification email requests to users awaiting verification. This lack of rate limiting can lead to service disruption and potential abuse of the email verification process. The issue has been rectified in version 1.1.1 by introducing a default rate limit of 10 minutes, thereby mitigating the risk of such attacks.
Affected Version(s)
Thorium 1.0.0 < 1.1.1
Thorium 1.1.1