CVE-2025-35436: Cisa Thorium
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote attacker could cause a crash by providing a specially crafted email address or response. Fixed in commit 6a65a27.
Affected products
- Cisa Thorium: up to and including 1.1.2
Published 2025-09-17. Last modified 2026-06-17.