CVE-2025-4639: Peergos

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Peergos through version 1.1.0.

Affected products

  • Peergos Peergos: version 1.1.0 only

Published 2025-05-14. Last modified 2026-06-17.