CVE-2026-31051 Details
Description
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Client Balance component
A denial-of-service vulnerability has been identified in HostBill versions 2025-11-24 and 2025-12-01. The issue allows a remote attacker to disrupt services via the Client Balance component by assigning negative balances to client accounts. This action freezes the client's actual balance and marks all purchases as overdue, regardless of payment status, leading to billing inconsistencies and service disruptions.
HostBill has released a security update for this vulnerability. Users are advised to update to the latest version, 2025-12-01, either manually or using the Auto-Update plugin.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 24, 2026CISA-ADP
Assessed Apr 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Muhammad5235/HostBill-CVEs-2025/blob/main/Business%20Logic%20Vulnerability/Business%20Logic%20Vulnerability | CISA-ADP | ExploitTechnical Description |
| https://blog.hostbillapp.com/2025/12/03/hostbill-security-advisory/ | [email protected] | AdvisoryRemedyVendor |
| https://github.com/Muhammad5235/HostBill-CVEs-2025/blob/main/Business%20Logic%20Vulnerability/Business%20Logic%20Vulnerability | [email protected] | ExploitTechnical Description |
| https://hostbillapp.com/changelog | [email protected] | Release NotesVendor |
| https://hostbillapp.com/release-notes/11-27-2025.html | [email protected] | Release NotesVendor |
| https://hostbillapp.com/release-notes/12-01-2025.html | [email protected] | Release NotesVendor |
| https://hostbillapp.com/responsible-disclosure | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| HostBill | 2025-11-24 2025-12-01 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | New CVE Received | [email protected] |
Volerion