CVE-2025-46556 - CVE House
Back to Database
Status published Medium CVE-2025-46556

MantisBT is Vulnerable to Denial-of-Service (DoS) attack via Excessive Note Length

Vulnerability Description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently corrupt issue activity logs by submitting extremely long notes (tested with 4,788,761 characters) due to a lack of server-side validation of note length. Once such a note is added, the activity stream UI fails to render; therefore, new notes cannot be displayed, effectively breaking all future collaboration on the issue. This issue is fixed in version 2.27.2.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-46556

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

mantisbt
Vulnerable Versions:
< 2.27.2

Timeline

Official Publish: November 4th, 2025
Last Modified: November 6th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)