cbcvebase.
CVE-2025-43816
published 2025-09-25

CVE-2025-43816: A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1…

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.31%
23.5th percentile
A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows an attacker to cause server unavailability (denial of service) via repeatedly calling the API endpoint.

Affected

11 ranges
VendorProductVersion rangeFixed in
liferaydigital_experience_platform< 7.47.4
liferaydigital_experience_platform
liferaydigital_experience_platform2023.Q3.1 – 2023.Q3.10
liferaydigital_experience_platform2023.q4.0 – 2023.q4.10
liferaydigital_experience_platform>= 2024.Q1.1 < 2024.Q1.62024.Q1.6
liferaydxp2023.Q3.1 – 2023.Q3.10
liferaydxp2023.Q4.0 – 2023.Q4.10
liferaydxp2024.Q1.1 – 2024.Q1.5
liferaydxp7.4.13 – 7.4.13-u92
liferayliferay_portal< 7.4.3.1207.4.3.120
liferayportal7.4.0 – 7.4.3.119

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.