CVE-2025-25065: Synacor Zimbra Collaboration Suite
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.
Affected products
- Synacor Zimbra Collaboration Suite: before 9.0.0 (fixed in 9.0.0); from 10.0.0, before 10.0.12 (fixed in 10.0.12); from 10.1.0, before 10.1.4 (fixed in 10.1.4); version 9.0.0 only
Published 2025-02-03. Last modified 2026-06-17.