Impact
Uncontrolled Resource Consumption in Adobe ColdFusion can allow a high‑privileged attacker to deplete system resources, causing the application to slow down or become unresponsive. The flaw is a basic resource exhaustion weakness, classified as CWE‑400.
Affected Systems
Adobe ColdFusion products released up through version 2023.18 and 2025.6 are affected. The vulnerability applies to all prior releases, including 2023.18, 2025.6, and earlier editions.
Risk and Exploitability
The CVSS score of 2.4 indicates a low severity rating, and the EPSS score is not available, implying no publicly known exploit prevalence. The vulnerability does not require user interaction and can be leveraged by anyone with high‑level privileges on the affected system. Based on the description, it is inferred that a high‑privileged attacker could trigger resource exhaustion, though the specific method is not detailed in the official remarks. The vulnerability is not listed in the CISA KEV catalog, so it has not been confirmed to be actively exploited in the wild.
OpenCVE Enrichment