CVE-2025-43816
published 2025-09-25CVE-2025-43816: A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.31%
23.5th percentile
A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows an attacker to cause server unavailability (denial of service) via repeatedly calling the API endpoint.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | < 7.4 | 7.4 |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | 2023.Q3.1 – 2023.Q3.10 | — |
| liferay | digital_experience_platform | 2023.q4.0 – 2023.q4.10 | — |
| liferay | digital_experience_platform | >= 2024.Q1.1 < 2024.Q1.6 | 2024.Q1.6 |
| liferay | dxp | 2023.Q3.1 – 2023.Q3.10 | — |
| liferay | dxp | 2023.Q4.0 – 2023.Q4.10 | — |
| liferay | dxp | 2024.Q1.1 – 2024.Q1.5 | — |
| liferay | dxp | 7.4.13 – 7.4.13-u92 | — |
| liferay | liferay_portal | < 7.4.3.120 | 7.4.3.120 |
| liferay | portal | 7.4.0 – 7.4.3.119 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Liferay Portal and DXP vulnerable to a memory leak
ghsa·2025-09-25
CVE-2025-43816 [MEDIUM] CWE-401 Liferay Portal and DXP vulnerable to a memory leak
Liferay Portal and DXP vulnerable to a memory leak
A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows an attacker to cause server unavailability (denial of service) via repeatedly calling the API endpoint.
OSV
Liferay Portal and DXP vulnerable to a memory leak
osv·2025-09-25
CVE-2025-43816 [MEDIUM] Liferay Portal and DXP vulnerable to a memory leak
Liferay Portal and DXP vulnerable to a memory leak
A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows an attacker to cause server unavailability (denial of service) via repeatedly calling the API endpoint.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-25
Published