Impact
ColdFusion is affected by an uncontrolled resource consumption vulnerability that can cause an application denial‑of‑service. An attacker can trigger the issue with crafted input, leading to exhaustion of system resources. The vulnerability does not require user interaction, so it can be exploited remotely.
Affected Systems
Adobe ColdFusion versions 2023 and 2025 are affected. No sub‑version ranges are listed, so all releases within these product lines are potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact on availability. EPSS is not available and the issue is not listed in the CISA KEV catalog, so the exact exploitation likelihood is unknown. Based on the description, the likely attack vector is network‑based; an attacker can send repetitive or large requests to trigger resource exhaustion without needing any user interaction.
OpenCVE Enrichment