CVE-2023-25499: Vaadin

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1 to 24.1.0.beta1, resulting in potential information disclosure.

Affected products

  • Vaadin Vaadin: from 10.0.0, before 10.0.23 (fixed in 10.0.23); from 11.0.0, before 14.10.1 (fixed in 14.10.1); from 15.0.0, up to and including 22.0.28; from 23.0.0, before 23.3.13 (fixed in 23.3.13); from 24.0.0, before 24.0.6 (fixed in 24.0.6); version 24.1.0 only

Published 2023-06-22. Last modified 2026-09-14.