CVE-2025-25207 - CVE House
Back to Database
Status published Medium CVE-2025-25207

Rhcl: authpolicy callbacks result in denial of service in authorino severity

Vulnerability Description

The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with developer persona to add callbacks to be executed to HTTP endpoints once the authorization process is completed. It was found that an attacker with developer persona access can add a large number of those callbacks to be executed by Authorino and as the authentication policy is enforced by a single instance of the service, this leada to a Denial of Service in Authorino while processing the post-authorization callbacks.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-25207

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat Connectivity Link 1
Vulnerable Versions:
1.0.1

Timeline

Official Publish: June 9th, 2025
Last Modified: March 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)