CVE-2025-65781

HIGH

Wekan <18.15 - DoS

Title source: llm
STIX 2.1

Description

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization bearer value as a userId and enters a non-terminating body-handling branch for any non-empty bearer token, enabling trivial application-layer DoS and latent identity-spoofing.

Scores

CVSS v3 8.2
EPSS 0.0008
EPSS Percentile 23.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-287 CWE-400
Status published
Products (1)
wekan_project/wekan < 8.16
Published Dec 15, 2025
Tracked Since Feb 18, 2026