logo

Last Week in AppSec for 21. October 2025

ID: da534fac-b444-50cc-9c49-8cf26ed4eee8

STIX ID: report--da534fac-b444-50cc-9c49-8cf26ed4eee8

Feed Name: Checkmarx Zero

Threat Score
60/100

Date Published: 2025-10-21

Date Updated: 2026-04-27

Author: Darren Meyer

...
...

This bulletin summarizes security issues: Authlib has two vulnerabilities (CVE-2025-61920 — oversized base64url segments causing severe memory/CPU exhaustion and DoS; CVE-2025-59420 — acceptance of unknown `crit` headers enabling policy bypass/possible privilege escalation), both fixed in Authlib 1.6.5; and Spring Framework has a CSRF bypass for STOMP-over-WebSocket endpoints (CVE-2025-41254) affecting several 5.x and 6.x versions, with upgrades and edge mitigations recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.