CVE-2025-26621 - CVE House
Back to Database
Status published High CVE-2025-26621

OpenCTI vulnerable to Denial of Service through web hook

Vulnerability Description

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.5.2, any user with the capability manage customizations can edit webhook that will execute javascript code. This can be abused to cause a denial of service attack by prototype pollution, making the node js server running the OpenCTI frontend become unavailable. Version 6.5.2 fixes the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-26621

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

OpenCTI-Platform

View all reports →

Affected Software

opencti
Vulnerable Versions:
< 6.5.2

Timeline

Official Publish: May 19th, 2025
Last Modified: May 19th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H

Weaknesses (CWE)