Denial of Service Vulnerability in Zimbra Collaboration Suite
CVE-2025-53645

7.5HIGH

Key Information:

Vendor

Zimbra

Vendor
CVE Published:
9 July 2025

What is CVE-2025-53645?

The Zimbra Collaboration Suite is susceptible to a denial of service due to improper handling of excessive comma-separated path segments in both its Webmail interface and Admin Console. An unauthenticated remote attacker can exploit this vulnerability by sending specially crafted GET requests that cause excessive processing and result in inflated responses. This behavior leads to uncontrolled resource consumption, ultimately triggering a denial of service condition. Users of versions before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 are at risk.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53645 : Denial of Service Vulnerability in Zimbra Collaboration Suite