THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-9467 — When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product ver

[NVD] CVE-2025-9467 — When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product ver

lownvdPublished 2025-09-04

CVE-2025-9467 CVSS: None Published: 2025-09-04T10:42:34.793

When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation.

Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:

Product version Vaadin 7.0.0 - 7.7.47 Vaadin 8.0.0 - 8.28.1 Vaadin 14

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-9467