U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-26865

Change History

CVE Modified by CVE 3/10/2025 10:15:25 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
http://www.openwall.com/lists/oss-security/2025/03/07/1

New CVE Received from Apache Software Foundation 3/10/2025 10:15:25 AM

Action Type Old Value New Value
Added Description

								
							
							
						
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.

This issue affects Apache OFBiz: from 18.12.17 before 18.12.18.  

It's a regression between 18.12.17 and 18.12.18.
In case you use something like that, which is not recommended!
For security, only official releases should be used.

In other words, if you use 18.12.17 you are still safe.
The version 18.12.17 is not a affected.
But something between 18.12.17 and 18.12.18 is.

In that case, users are recommended to upgrade to version 18.12.18, which fixes the issue.
Added CWE

								
							
							
						
CWE-1336
Added Reference

								
							
							
						
https://issues.apache.org/jira/browse/OFBIZ-12594
Added Reference

								
							
							
						
https://lists.apache.org/thread/prb48ztk01bflyyjbl6p56wlcc1n5sz7
Added Reference

								
							
							
						
https://ofbiz.apache.org/download.html
Added Reference

								
							
							
						
https://ofbiz.apache.org/security.html