CVE-2025-66473: 
Java vulnerability analysis and mitigation

Overview

CVE-2025-66473 is an unauthenticated Denial of Service vulnerability in XWiki's REST API caused by the absence of any request size or item count limits. Affected versions include all releases below 16.10.11, versions 17.0.0-rc-1 through 17.4.3, and versions 17.5.0-rc-1 through 17.6.0 (package org.xwiki.platform:xwiki-platform-rest-server). The vulnerability was disclosed on December 10, 2025, by XWiki maintainer michitux via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (Github Advisory, XWiki Advisory).

Technical details

The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling): XWiki's REST API endpoints do not impose any pagination or item-count restrictions on responses. For example, a GET request to /rest/wikis/xwiki/spaces returns all spaces in the wiki — effectively all pages — in a single response, with no server-side cap. An unauthenticated remote attacker can repeatedly issue such requests, forcing the server to load and serialize the entire wiki content into memory, leading to memory exhaustion and potential Out-of-Memory (OOM) conditions. No special preconditions, credentials, or user interaction are required; the REST API is accessible over the network by default (XWiki Advisory, Patch Commit).

Impact

Successful exploitation results in significant performance degradation and potential complete unavailability of the XWiki instance, constituting a Denial of Service (DoS). On large wikis with many pages, repeated unbounded API requests can exhaust JVM heap memory, causing Out-of-Memory errors and crashing the wiki service. There is no confidentiality or integrity impact — the vulnerability is purely an availability concern affecting the vulnerable system (XWiki Advisory, Github Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (Github Advisory). The vulnerability is trivially exploitable by any unauthenticated network attacker using standard HTTP tools, requiring no special knowledge beyond knowing the affected endpoint paths. The EPSS score is approximately 0.038% (12th percentile), indicating a low current probability of exploitation in the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing XWiki instances running affected versions (below 16.10.11, or 17.0.0-rc-1 through 17.4.3, or 17.5.0-rc-1 through 17.6.0) using tools like Shodan or Censys, searching for XWiki REST API endpoints.
  2. Identify vulnerable REST endpoints: Target known unbounded REST API resources such as /rest/wikis/xwiki/spaces, /rest/wikis/xwiki/pages, or similar collection endpoints that return all items without pagination.
  3. Send unbounded requests: Issue repeated unauthenticated HTTP GET requests to the identified endpoints without specifying any limit parameter (or with a very large limit), e.g.:
    curl -s http://target-xwiki/rest/wikis/xwiki/spaces
  4. Amplify the attack: Automate and parallelize requests using tools like ab (Apache Bench), wrk, or custom scripts to maximize memory pressure on the server.
  5. Achieve DoS: The server attempts to load and serialize all wiki pages/spaces into memory for each request, exhausting JVM heap and causing slowness or an OOM crash, rendering the wiki unavailable (XWiki Advisory).

Indicators of compromise

  • Network: High volume of unauthenticated HTTP GET requests to XWiki REST API endpoints such as /rest/wikis/xwiki/spaces, /rest/wikis/xwiki/pages, /rest/wikis/xwiki/classes, or similar collection resources; requests originating from a single or small set of IP addresses in rapid succession.
  • Logs: XWiki access logs showing repeated requests to /rest/ endpoints without authentication headers and without start/number pagination parameters; Java heap-related error messages (e.g., java.lang.OutOfMemoryError: Java heap space) in XWiki application logs.
  • Process: Abnormal JVM memory consumption by the XWiki process; garbage collection logs showing frequent full GC cycles or GC overhead limit exceeded errors; XWiki service becoming unresponsive or restarting unexpectedly.

Mitigation and workarounds

Upgrade to XWiki versions 16.10.11, 17.4.4, or 17.7.0-rc-1 (or later), which introduce a configurable server-side limit of 1,000 items per REST API response by default; requests exceeding this limit now return an error (XWiki Advisory, Patch Commit). If immediate upgrade is not possible, the only known workaround is to block or restrict access to the affected REST API resources at a reverse proxy or WAF layer in front of XWiki. Additionally, administrators should implement rate limiting on REST API endpoints and monitor for anomalous high-volume API request patterns.

Additional resources


Source: This report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103922CRITICAL9.3
  • JavaScript logoJavaScript
  • com.capacitorjs:core
NoYesOct 01, 2026
CVE-2026-61741CRITICAL9.3
  • Java logoJava
  • org.http4s:http4s-scala-xml_2.12
NoYesSep 24, 2026
CVE-2026-54049HIGH8.7
  • Java logoJava
  • org.sakaiproject.rubrics:rubrics-impl
NoNoOct 01, 2026
CVE-2026-100660HIGH8.7
  • Java logoJava
  • io.netty:netty-codec-http3
NoNoSep 26, 2026
CVE-2026-61586HIGH8.2
  • Java logoJava
  • eu.copernik:copernik-xml-factory
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management