cbcvebase.
CVE-2025-43764
published 2025-08-23

CVE-2025-43764: Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through…

PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.29%
21.0th percentile
Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92, which allows authenticated users with permissions to update Kaleo Workflows to enter a malicious Regex pattern causing their browser to hang for a very long time.

Affected

12 ranges
VendorProductVersion rangeFixed in
liferaydigital_experience_platform
liferaydigital_experience_platform2024.Q1.1 – 2024.Q1.20
liferaydigital_experience_platform>= 2024.Q4.0 < 2024.Q4.22024.Q4.2
liferaydigital_experience_platform2024.q2.0 – 2024.q2.13
liferaydigital_experience_platform2024.q3.1 – 2024.q3.13
liferaydxp2024.Q1.1 – 2024.Q1.20
liferaydxp2024.Q2.1 – 2024.Q2.13
liferaydxp2024.Q3.0 – 2024.Q3.13
liferaydxp2024.Q4.0 – 2024.Q4.1
liferaydxp7.4.13 – 7.4.13-u92
liferayliferay_portal>= 7.4.0 < 7.4.3.1327.4.3.132
liferayportal7.4.3.0 – 7.4.3.131

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.