Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29732 | CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote attacker could cause a crash by providing a specially crafted email address or response. Fixed in commit 6a65a27. |
Fri, 19 Dec 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:cisa:thorium:*:*:*:*:*:*:*:* |
Tue, 30 Sep 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Sep 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisa
Cisa thorium |
|
| Vendors & Products |
Cisa
Cisa thorium |
Wed, 17 Sep 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote attacker could cause a crash by providing a specially crafted email address or response. Fixed in commit 6a65a27. | |
| Title | CISA Thorium account verification email error handling | |
| Weaknesses | CWE-248 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2025-09-30T16:36:16.594Z
Reserved: 2025-04-15T20:57:14.281Z
Link: CVE-2025-35436
Updated: 2025-09-30T16:36:11.337Z
Status : Analyzed
Published: 2025-09-17T17:15:44.037
Modified: 2025-12-19T12:34:10.813
Link: CVE-2025-35436
No data.
OpenCVE Enrichment
Updated: 2025-09-18T12:41:08Z
EUVD