GHSA-vhgc-6rjx-f6vv · Severity: medium — Account users are allowed by default to register templates to be downloaded directly to the...
Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to missing file name sanitization, an attacker can register malicious templates to execute arbitrary code on the KVM hosts. This can result in the compromise of resource integrity and confidentiality, data loss, denial of service, and availability of the KVM-based infrastructure managed by CloudStack. Users are recommended to upgrade to Apache CloudStack versions 4.20.3.0 or 4.22.0.1, or later, which fixes this issue.
Conclusion & alert: CVE-2026-25077 is rated Low Risk (39.1/100): CVSS High severity, with low exploitation likelihood (EPSS 0.04%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-09 | — | 0.04% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-vhgc-6rjx-f6vv · Severity: medium — Account users are allowed by default to register templates to be downloaded directly to the...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | cloudstack | >= 4.11.0.0, < 4.20.3.0 | cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:* |
| apache | cloudstack | >= 4.21.0.0, < 4.22.0.1 | cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://lists.apache.org/thread/n8mt5b7wkpysstb8w7rr9f02kc5cq2xm | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/05/09/6 |