CVE-2025-46171

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
23/07/2025
Last modified:
28/07/2025

Description

vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently large buddy list, processing the list can consume excessive memory, exhausting system resources and crashing the forum.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vbulletin:vbulletin:3.8.7:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools