CVE-2025-3602
HIGHLiferay Portal 7.4.0-7.4.3.97 and Liferay DXP 2023.Q3.1-2023.Q3.2 - Denial of Service via GraphQL Query Depth
Title source: llmDescription
Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing complex queries.
References (1)
Core 1
Core References
Scores
CVSS v3
7.5
EPSS
0.0055
EPSS Percentile
68.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (3)
com.liferay/com.liferay.portal.vulcan.impl
0 - 5.0.103Maven
liferay/digital_experience_platform
7.2 fix_pack_10 (13 CPE variants)
liferay/digital_experience_platform
7.3 (36 CPE variants)
Published
Jun 16, 2025
Tracked Since
Feb 18, 2026