CVE-2024-4227: Genivia Gsoap

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate ID attributes which can lead to a DoS.

Affected products

  • Genivia Gsoap: from 2.8.24, up to and including 2.8.132

Published 2025-01-15. Last modified 2026-06-17.