Allocation of Resources Without Limits or Throttling in XWiki platform - CVE-2025-66473
Published: May 5, 2026
XWiki platform
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in REST APIs when handling requests for large numbers of items. A remote attacker can send a request for an excessive number of items to cause a denial of service.
On large wikis, exploitation can lead to slowness or out-of-memory conditions.