PT-2025-28029 · Alinto+1 · Sogo+1

Stefan Bühler

·

Published

2025-07-05

·

Updated

2025-10-31

·

CVE-2025-53603

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Alinto SOPE SOGo versions 2.0.2 through 5.12.2
Description This issue involves a NULL pointer dereference in sope-core/NGExtensions/NGHashMap.m that can lead to a crash of the SOGo application. The vulnerability occurs when a request contains a parameter in the query string that duplicates a parameter in the POST body. Approximately 30,000 installations of SOGo are tracked in the Russian internet space, with an estimated 98% being vulnerable. While mass exploitation has not been observed, the vulnerability allows for remote, unauthenticated denial-of-service attacks.
Recommendations Update SOGo to version 5.12.3 or later to resolve this issue. Restart the service to reset active sessions.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-53603
DLA-4260-1
DSA-5970-1
MGASA-2025-0255

Affected Products

Debian
Sogo