CVE-2024-48938: Znuny
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied from Microsoft Word could lead to high CPU usage and block the parsing process.
Affected products
- Znuny Znuny: from 6.0.0, before 6.1.0 (fixed in 6.1.0); from 6.5.1, up to and including 6.5.10; from 7.0.1, up to and including 7.0.16
Published 2024-10-11. Last modified 2026-06-17.