Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0.31.0, the private data exports can lead to data leaks in case the UUID generation, causing collisions for the generated UUIDs. This issue has been patched in versions 0.30.4 and 0.31.0.
References
| Link | Resource |
|---|---|
| https://github.com/decidim/decidim/pull/13571 | Issue Tracking Patch |
| https://github.com/decidim/decidim/releases/tag/v0.30.4 | Release Notes |
| https://github.com/decidim/decidim/releases/tag/v0.31.0 | Release Notes |
| https://github.com/decidim/decidim/security/advisories/GHSA-3cx6-j9j4-54mp | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
23 Feb 2026, 17:32
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:decidim:decidim:*:*:*:*:*:ruby:*:* cpe:2.3:a:decidim:decidim:0.31.0:rc1:*:*:*:ruby:*:* cpe:2.3:a:decidim:decidim:0.31.0:rc2:*:*:*:ruby:*:* |
|
| References | () https://github.com/decidim/decidim/pull/13571 - Issue Tracking, Patch | |
| References | () https://github.com/decidim/decidim/releases/tag/v0.30.4 - Release Notes | |
| References | () https://github.com/decidim/decidim/releases/tag/v0.31.0 - Release Notes | |
| References | () https://github.com/decidim/decidim/security/advisories/GHSA-3cx6-j9j4-54mp - Vendor Advisory | |
| First Time |
Decidim
Decidim decidim |
|
| Summary |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
03 Feb 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-03 15:16
Updated : 2026-02-23 17:32
NVD link : CVE-2025-65017
Mitre link : CVE-2025-65017
CVE.ORG link : CVE-2025-65017
JSON object : View
Products Affected
decidim
- decidim
