
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66473 is an unauthenticated Denial of Service vulnerability in XWiki's REST API caused by the absence of any request size or item count limits. Affected versions include all releases below 16.10.11, versions 17.0.0-rc-1 through 17.4.3, and versions 17.5.0-rc-1 through 17.6.0 (package org.xwiki.platform:xwiki-platform-rest-server). The vulnerability was disclosed on December 10, 2025, by XWiki maintainer michitux via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (Github Advisory, XWiki Advisory).
The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling): XWiki's REST API endpoints do not impose any pagination or item-count restrictions on responses. For example, a GET request to /rest/wikis/xwiki/spaces returns all spaces in the wiki — effectively all pages — in a single response, with no server-side cap. An unauthenticated remote attacker can repeatedly issue such requests, forcing the server to load and serialize the entire wiki content into memory, leading to memory exhaustion and potential Out-of-Memory (OOM) conditions. No special preconditions, credentials, or user interaction are required; the REST API is accessible over the network by default (XWiki Advisory, Patch Commit).
Successful exploitation results in significant performance degradation and potential complete unavailability of the XWiki instance, constituting a Denial of Service (DoS). On large wikis with many pages, repeated unbounded API requests can exhaust JVM heap memory, causing Out-of-Memory errors and crashing the wiki service. There is no confidentiality or integrity impact — the vulnerability is purely an availability concern affecting the vulnerable system (XWiki Advisory, Github Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (Github Advisory). The vulnerability is trivially exploitable by any unauthenticated network attacker using standard HTTP tools, requiring no special knowledge beyond knowing the affected endpoint paths. The EPSS score is approximately 0.038% (12th percentile), indicating a low current probability of exploitation in the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.
/rest/wikis/xwiki/spaces, /rest/wikis/xwiki/pages, or similar collection endpoints that return all items without pagination.curl -s http://target-xwiki/rest/wikis/xwiki/spacesab (Apache Bench), wrk, or custom scripts to maximize memory pressure on the server./rest/wikis/xwiki/spaces, /rest/wikis/xwiki/pages, /rest/wikis/xwiki/classes, or similar collection resources; requests originating from a single or small set of IP addresses in rapid succession./rest/ endpoints without authentication headers and without start/number pagination parameters; Java heap-related error messages (e.g., java.lang.OutOfMemoryError: Java heap space) in XWiki application logs.Upgrade to XWiki versions 16.10.11, 17.4.4, or 17.7.0-rc-1 (or later), which introduce a configurable server-side limit of 1,000 items per REST API response by default; requests exceeding this limit now return an error (XWiki Advisory, Patch Commit). If immediate upgrade is not possible, the only known workaround is to block or restrict access to the affected REST API resources at a reverse proxy or WAF layer in front of XWiki. Additionally, administrators should implement rate limiting on REST API endpoints and monitor for anomalous high-volume API request patterns.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."