CVE-2025-35436

CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote attacker could cause a crash by providing a specially crafted email address or response. Fixed in commit 6a65a27.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisa:thorium:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:14

Type Values Removed Values Added
Summary
  • (es) CISA Thorium utiliza '.unwrap()' para manejar errores relacionados con mensajes de correo electrónico de verificación de cuenta. Un atacante remoto no autenticado podría causar una caída al proporcionar una dirección de correo electrónico o respuesta especialmente diseñada. Corregido en el commit 6a65a27.

19 Dec 2025, 12:34

Type Values Removed Values Added
References () https://github.com/mjcarson/thorium/commit/6a65a2711fb2387e8c3eacebc774053741bf5aeb - () https://github.com/mjcarson/thorium/commit/6a65a2711fb2387e8c3eacebc774053741bf5aeb - Patch
References () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-259-01.json - () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-259-01.json - Third Party Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-35436 - () https://www.cve.org/CVERecord?id=CVE-2025-35436 - Third Party Advisory
CPE cpe:2.3:a:cisa:thorium:*:*:*:*:*:*:*:*
First Time Cisa thorium
Cisa

17 Sep 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-17 17:15

Updated : 2026-06-17 09:14


NVD link : CVE-2025-35436

Mitre link : CVE-2025-35436

CVE.ORG link : CVE-2025-35436


JSON object : View

Products Affected

cisa

  • thorium
CWE
CWE-248

Uncaught Exception