{"id":"CVE-2025-43880","details":"Inefficient regular expression complexity issue exists in GROWI prior to v7.1.6. If exploited, a logged-in user may cause a denial of service (DoS) condition.","modified":"2026-07-15T01:49:15.925724730Z","published":"2025-06-25T05:31:29.560Z","database_specific":{"cna_assigner":"jpcert","cwe_ids":["CWE-1333"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/43xxx/CVE-2025-43880.json"},"references":[{"type":"WEB","url":"https://jvn.jp/en/jp/JVN21624250/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/43xxx/CVE-2025-43880.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-43880"},{"type":"FIX","url":"https://github.com/weseek/growi/pull/9487"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/growilabs/growi","events":[{"introduced":"9d3b120b50644ef86837432d9cc8f921eb896888"},{"last_affected":"9d3b120b50644ef86837432d9cc8f921eb896888"}],"database_specific":{"extracted_events":[{"introduced":"prior to v7.1.6"},{"last_affected":"prior to v7.1.6"}],"source":"AFFECTED_FIELD"}}],"versions":["prior to v7.1.6","v7.1.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-43880.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}