CVE-2025-2529: IBM Terracotta
Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.
Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application using Ehcache utilizes keys sourced from (malicious) external parties in an unfiltered/unsalted way.
Affected products
- IBM Terracotta: from 10.15.0, before 10.15.0.23 (fixed in 10.15.0.23); from 11.1.0, before 11.1.0.5 (fixed in 11.1.0.5)
Published 2025-10-15. Last modified 2026-10-08.