Input validation error in Splunk Enterprise and Splunk Secure Gateway - CVE-2025-20389
Published: December 4, 2025
Splunk Enterprise
Splunk Secure Gateway
Detailed vulnerability description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the "label" column field in Splunk Secure Gateway App. A remote user can pass a malicious payload through the label column field after adding a new device in the Splunk Secure Gateway app and perform a denial of service attack.