Liferay Portal and DXP vulnerable to a memory leak
Moderate severity
GitHub Reviewed
Published
Sep 25, 2025
to the GitHub Advisory Database
•
Updated Sep 26, 2025
Package
Affected versions
< 5.0.115
Patched versions
5.0.115
Description
Published by the National Vulnerability Database
Sep 25, 2025
Published to the GitHub Advisory Database
Sep 25, 2025
Reviewed
Sep 26, 2025
Last updated
Sep 26, 2025
A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows an attacker to cause server unavailability (denial of service) via repeatedly calling the API endpoint.
References