github.com
https://github.com/OSC/ondemand/commit/40800d68cd019c5f1c48b2deafebba6dff4abee2 CVE-2025-53636
MEDIUM
Open OnDemand Shell App closed websocket DoS
Record summary
CVE-2025-53636 has a selected CVSS score of 5.4 (medium).
Description
Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs can create very large log files causing a Denial of Service (DoS) to the ondemand system. This vulnerability is fixed in 3.1.14 and 4.0.6.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 14, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ondemandBrowse OSC / ondemand | CVE List | >= 1.6, < 3.1.14 | affected |
| >= 4.0.0-0.rc1, < 4.0.6 | affected |
References
3github.com
https://github.com/OSC/ondemand/commit/96f29b995e1add7562516614e4dc8d961987e8b4 github.comConfirmation
https://github.com/OSC/ondemand/security/advisories/GHSA-x5xv-fw37-v524