Junglewise Threat Intelligence

CVE-2025-43813: Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet

CVE-2025-43813 · Severity: medium · CVSS 4 · Published 2025-09-30

Technologies: com.liferay.portal:com.liferay.portal.impl (Maven), com.liferay.portal:release.portal.bom (Maven). Vendors: Maven.

Executive brief

Liferay Portal vulnerable to path traversal and denial-of-service in the ComboServlet

Affected products

  • Maven com.liferay.portal:com.liferay.portal.impl
  • Maven com.liferay.portal:release.portal.bom

Related threats