vulnerability
Red Hat JBoss EAP: CVE-2025-32395: Exposure of Sensitive Information to an Unauthorized Actor
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:M/Au:N/C:C/I:N/A:N) | Apr 10, 2025 | Apr 13, 2025 | Nov 26, 2025 |
Severity
7
CVSS
(AV:N/AC:M/Au:N/C:C/I:N/A:N)
Published
Apr 10, 2025
Added
Apr 13, 2025
Modified
Nov 26, 2025
Description
Vite is a frontend tooling framework for javascript. Prior to 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13, the contents of arbitrary files can be returned to the browser if the dev server is running on Node or Bun. HTTP 1.1 spec (RFC 9112) does not allow # in request-target. Although an attacker can send such a request. For those requests with an invalid request-line (it includes request-target), the spec recommends to reject them with 400 or 301. The same can be said for HTTP 2. On Node and Bun, those requests are not rejected internally and is passed to the user land. For those requests, the value of http.IncomingMessage.url contains #. Vite assumed req.url won't contain # when checking server.fs.deny, allowing those kinds of requests to bypass the check. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) and running the Vite dev server on runtimes that are not Deno (e.g. Node, Bun) are affected. This vulnerability is fixed in 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13.. A flaw was found in Vite. This vulnerability allows arbitrary file access via specially crafted HTTP requests containing a # character in the request URL. The issue occurs when the server is run on Node.js or Bun and exposed to the network. Improper handling of invalid request lines allows these requests to bypass security checks that restrict file access.
Solution
red-hat-jboss-eap-upgrade-latest
References
- CWE-200
- CVE-2025-32395
- https://attackerkb.com/topics/CVE-2025-32395
- URL-https://access.redhat.com/security/cve/CVE-2025-32395
- URL-https://bugzilla.redhat.com/show_bug.cgi?id=2358861
- URL-https://github.com/vitejs/vite/commit/175a83909f02d3b554452a7bd02b9f340cdfef70
- URL-https://github.com/vitejs/vite/security/advisories/GHSA-356w-63v5-8wf4
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.