Input validation error in Splunk Secure Gateway and Splunk Enterprise - CVE-2025-20389
Published: December 4, 2025
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the "label" column field in Splunk Secure Gateway App. A remote user can pass a malicious payload through the label column field after adding a new device in the Splunk Secure Gateway app and perform a denial of service attack.
Affected software
Splunk Enterprise
How to mitigate CVE-2025-20389
Splunk Enterprise - addressed in versions 9.2.10, 9.3.8, 9.4.6, 10.0.2