Back to search
CVE-2025-43816
Published: Sep 25, 2025
Modified: Sep 26, 2025
PUBLISHED
Description
A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows an attacker to cause server unavailability (denial of service) via repeatedly calling the API endpoint.
| Vendor | Product | Versions |
|---|---|---|
Liferay | Portal | affected 7.4.0 - <= 7.4.3.119 |
Liferay | DXP | affected 7.4.13 - <= 7.4.13-u92affected 2023.Q3.1 - <= 2023.Q3.10affected 2023.Q4.0 - <= 2023.Q4.10affected 2024.Q1.1 - <= 2024.Q1.5 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now