CVE-2025-65899 Details
Description
Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application returns different error messages for invalid users (user_not_found) versus valid users with incorrect passwords (invalid_password). This observable response discrepancy allows unauthenticated attackers to enumerate valid usernames on the system.
A user enumeration vulnerability has been identified in Kalmia CMS version 0.2.0. The issue arises in the authentication process, where the application delivers distinct error messages for invalid usernames compared to valid usernames with incorrect passwords. This inconsistency allows unauthenticated attackers to identify valid usernames on the platform.
Users are advised to update to the patched version of Kalmia CMS, which is available on the project's GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/DifuseHQ/Kalmia | [email protected] | Product |
| https://github.com/Noxurge/CVE-2025-65899/blob/main/README.md | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-204 | Observable Response Discrepancy | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| difuse kalmia | 0.2.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 10, 2025 | Initial Analysis | [email protected] |
| Dec 8, 2025 | CVE Modified | CISA-ADP |
| Dec 4, 2025 | New CVE Received | [email protected] |