CVE-2026-27308Uncontrolled Resource Consumption in Adobe Coldfusion

Severity
2.4LOWNVD
EPSS
0.0%
top 95.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 14
Latest updateApr 15

Description

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:LExploitability: 0.9 | Impact: 1.4

Affected Packages1 packages

CVEListV5adobe/coldfusion2025.6

🔴Vulnerability Details

2
GHSA
GHSA-rrr4-c4r3-6q77: ColdFusion versions 20232026-04-15
CVEList
ColdFusion | Uncontrolled Resource Consumption (CWE-400)2026-04-14
CVE-2026-27308 — Uncontrolled Resource Consumption | cvebase