Input validation error in Shopware - CVE-2025-30151
Published: April 8, 2025 / Updated: May 20, 2026
Shopware
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in password handling in Storefront forms or Store-API when processing excessively long passwords. A remote attacker can submit a specially crafted request with a long password to cause a denial of service.