CVE-2019-25355

Severity CVSS v4.0:
HIGH
Type:
CWE-22 Path Traversal
Publication date:
18/02/2026
Last modified:
26/02/2026

Description

gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniques. Attackers can retrieve sensitive files like /etc/passwd by sending crafted GET requests with multiple '../' directory traversal sequences.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:genivia:gsoap:2.8.0:*:*:*:*:*:*:*