CVE-2025-24026

iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of service (ReDoS) that may, under some circumstances, affect iTop server. Version 3.2.1 doesn't use the affected variable in the regular expression. As a workaround, if iTop app_root_url is defined in the configuration file, then there is no possible way to exploit this ReDoS.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*

History

01 Aug 2025, 18:39

Type Values Removed Values Added
First Time Combodo itop
Combodo
CPE cpe:2.3:a:combodo:itop:*:*:*:*:*:*:*:*
References () https://github.com/Combodo/iTop/security/advisories/GHSA-9g7f-jmc3-rrmf - () https://github.com/Combodo/iTop/security/advisories/GHSA-9g7f-jmc3-rrmf - Vendor Advisory

14 May 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-14 15:15

Updated : 2025-08-01 18:39


NVD link : CVE-2025-24026

Mitre link : CVE-2025-24026


JSON object : View

Products Affected

combodo

  • itop
CWE
CWE-1333

Inefficient Regular Expression Complexity