CVE-2025-3526 Details
Description
SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.
A denial-of-service vulnerability has been identified in Liferay Portal versions 7.0.0 through 7.4.3.21, as well as in Liferay DXP versions 7.4 GA through update 9, 7.3 GA through update 25, 7.2, 7.1, and 7.0. These versions do not properly restrict the saving of request parameters in the HTTP session. This oversight allows remote attackers to craft HTTP requests that consume system memory, creating denial-of-service conditions.
Users can upgrade to Liferay Portal 7.4.3.22 or Liferay DXP 7.4 Update 10, 7.3 Update 26. Instructions for downloading these versions are available on the Liferay GitHub release page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-3526 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| liferay digital experience platform | >= 7.0, <= 7.2 7.3 - 7.3 update1 7.3 update10 7.3 update11 7.3 update12 7.3 update13 7.3 update14 7.3 update15 7.3 update16 7.3 update17 7.3 update18 7.3 update19 7.3 update2 7.3 update20 7.3 update21 7.3 update22 7.3 update23 7.3 update24 7.3 update25 7.3 update3 7.3 update4 7.3 update5 7.3 update6 7.3 update7 7.3 update8 7.3 update9 7.4 - 7.4 update1 7.4 update2 7.4 update3 7.4 update4 7.4 update5 7.4 update6 7.4 update7 7.4 update8 7.4 update9 |
CPE
Remediation
| |
| liferay liferay portal | >= 7.0.0, <= 7.4.3.21 6.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 16, 2025 | Initial Analysis | [email protected] |
| Jun 16, 2025 | New CVE Received | [email protected] |