PT-2025-38235 · Unknown · Cisa Thorium

Published

2025-09-17

·

Updated

2026-03-10

·

CVE-2025-35436

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions CISA Thorium (affected versions not specified)
Description The software utilizes '.unwrap()' for error handling related to account verification email messages. An unauthenticated remote attacker can trigger a crash by submitting a specially crafted email address or response. The issue is addressed in commit 6a65a27.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-35436

Affected Products

Cisa Thorium