Impact
ColdFusion versions 2025.9, 2023.20 and earlier contain a server‑side request forgery flaw (CWE‑918). The defect allows an attacker to craft outbound HTTP requests from the server to arbitrary destinations, bypassing built‑in security functions and returning data that should otherwise remain inaccessible. The vulnerability results in unauthorized data disclosure and enables traversal of internal boundaries, as the access scope is explicitly changed.
Affected Systems
Adobe ColdFusion, specifically any release prior to 2025.9 and 2023.20, remains impacted regardless of the underlying operating system. Any deployed instance that accepts network requests from potentially untrusted clients is considered vulnerable.
Risk and Exploitability
The CVSS score of 8.6 classifies the issue as high severity. No EPSS value is provided and the vulnerability is not listed in the CISA KEV catalog, yet the lack of user interaction and the changed scope imply a straightforward exploitation path once an attacker can issue arbitrary requests to the vulnerable server. The likely attack vector is remote, through networkexposed endpoints that accept input. Fast mitigation is essential to prevent data leakage.
OpenCVE Enrichment