CVE-2025-9467
Java vulnerability analysis and mitigation

Overview

CVE-2025-9467 is a vulnerability in Vaadin Upload's start listener functionality that allows bypassing file upload validation on the server-side. The vulnerability was disclosed on September 4, 2025, and affects multiple versions of Vaadin products including Vaadin 7.0.0-7.7.47, 8.0.0-8.28.1, 14.0.0-14.13.0, 23.0.0-23.6.1, and 24.0.0-24.7.6 (Vaadin Advisory).

Technical details

The vulnerability is classified as an Improper Input Validation (CWE-20) issue with a CVSS v4.0 base score of 5.3 (Medium). The attack vector is network-based (AV:N) with low attack complexity (AC:L), requiring low privileges (PR:L) and no user interaction (UI:N). The vulnerability can lead to limited impact on integrity (VI:L) and availability (VA:L) with no impact on confidentiality (VC:N) (Vaadin Advisory).

Impact

When exploited, this vulnerability allows attackers to bypass server-side validation mechanisms for file uploads in Vaadin applications. This could potentially lead to unauthorized file uploads, affecting the integrity and availability of the application (Snyk).

Mitigation and workarounds

Users are advised to upgrade to the fixed versions: Vaadin 7.7.48, 8.28.2, 14.13.1, 23.6.2, or 24.7.7 or newer. For Vaadin Upload Flow component, users should upgrade to versions 14.13.1, 23.6.2, or 24.7.7 or newer. Note that Vaadin versions 10-13 and 15-22 are no longer supported and users should update to the latest 14, 23, or 24 version (Vaadin Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-29847HIGH7.5
  • JavaJava
  • org.apache.linkis:linkis
NoYesJan 19, 2026
CVE-2026-1050MEDIUM6.9
  • JavaJava
  • net.risesoft:risenet-y9boot-support-platform-service
NoNoJan 17, 2026
CVE-2025-15104MEDIUM6.9
  • JavaScriptJavaScript
  • vnu-jar
NoNoJan 16, 2026
CVE-2025-59355MEDIUM6.5
  • JavaJava
  • org.apache.linkis:linkis-metadata
NoYesJan 19, 2026
CVE-2026-0858MEDIUM5.1
  • JavaJava
  • net.sourceforge.plantuml:plantuml
NoYesJan 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management