Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. com.liferay/com.liferay.portal.vulcan.impl
  4. ›
  5. CVE-2025-43816

CVE-2025-43816: Liferay Portal and DXP vulnerable to a memory leak

September 25, 2025 (updated September 26, 2025)

A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows an attacker to cause server unavailability (denial of service) via repeatedly calling the API endpoint.

References

  • github.com/advisories/GHSA-hrqm-qpw9-w8rv
  • github.com/liferay/liferay-portal
  • liferay.atlassian.net/browse/LPE-18005
  • liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-43816
  • nvd.nist.gov/vuln/detail/CVE-2025-43816

Code Behaviors & Features

Detect and mitigate CVE-2025-43816 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 5.0.115

Fixed versions

  • 5.0.115

Solution

Upgrade to version 5.0.115 or above.

Weakness

  • CWE-401: Missing Release of Memory after Effective Lifetime

Source file

maven/com.liferay/com.liferay.portal.vulcan.impl/CVE-2025-43816.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 29 Sep 2025 00:19:17 +0000.