CVE-2025-14591

HIGH

Delphix Continuous Compliance >=2025.3.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited files, an issue was identified: using an incorrect EOR configuration can cause inaccurate parsing and leave personally identifiable information (PII) unmasked.

Scores

CVSS v3 7.5
EPSS 0.0024
EPSS Percentile 14.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
perforce/delphix_continuous_compliance 2025.3.0.0 - 2025.6.0.0
Published Dec 20, 2025
Tracked Since Feb 18, 2026