CVE-2026-25957: Cube Cube.js
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. This vulnerability is fixed in 1.5.13 and 1.4.2.
Affected products
- Cube Cube.js: from 1.1.17, before 1.4.2 (fixed in 1.4.2); from 1.5.0, before 1.5.13 (fixed in 1.5.13)
Published 2026-02-09. Last modified 2026-06-17.