Junglewise Threat Intelligence

CVE-2025-12767: IBM Concert regular expression denial of service

CVE-2025-12767 · Severity: medium · CVSS 5.3 · Published 2026-09-22

Technologies: IBM Concert. Vendors: IBM.

Executive brief

IBM Concert is a software platform used by enterprises for application development and integration. A flaw in how the product processes user-supplied regular expressions allows a remote attacker to cause the application to consume excessive system resources and become unresponsive, disrupting business operations without requiring authentication.

Technical details

The vulnerability is a regular expression denial of service (ReDoS) flaw affecting IBM Concert versions 1.0.0 through 3.0.0. An unauthenticated remote attacker can craft a malicious regular expression that triggers catastrophic backtracking, causing excessive CPU and memory consumption. The attack requires network access but no special privileges or user interaction.

Affected products

  • IBM Concert 1.0.0 through 3.0.0

Timeline

  • 2026-09-22: disclosed

References

Related threats