CVE-2025-3526: Liferay Digital Experience Platform

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.

Affected products

  • Liferay Digital Experience Platform: from 7.0, up to and including 7.2; version 7.3 only; version 7.4 only
  • Liferay Liferay Portal: from 7.0.0, up to and including 7.4.3.21; version 6.2 only

Published 2025-06-16. Last modified 2026-06-17.