Junglewise Threat Intelligence

CVE-2025-65518: Plesk Obsidian Denial of Service in get_password.php

CVE-2025-65518 · Severity: high · CVSS 7.5 · Published 2026-01-08

Technologies: Plesk. Vendors: WebPros, Plesk.

Executive brief

Plesk Obsidian, a widely used web hosting and server management platform, is vulnerable to a flaw that allows attackers to disable its web interface. By sending a specifically crafted request to the password recovery page, an attacker can force the interface into an infinite reload loop. This prevents legitimate administrators and users from accessing the management panel, potentially disrupting server operations and maintenance.

Technical details

A Denial of Service (DoS) vulnerability exists in the get_password.php endpoint of Plesk Obsidian (versions 8.0.1 to 18.0.73). The flaw is categorized under CWE-400 (Uncontrolled Resource Consumption) and CWE-606 (Unchecked Input for Loop Condition). An unauthenticated remote attacker can send a crafted request containing a malicious payload that causes the web interface to enter an infinite reload loop, characterized by continuous 'Bad Request' responses. This effectively locks users out of the web-based management console. The issue is addressed in Plesk Obsidian version 18.0.74 and later.

Affected products

  • Plesk Plesk Obsidian 8.0.1 through 18.0.73

Timeline

  • 2026-01-08: disclosed
  • 2026-01-08: advisory: NVD publication date

References