CVE-2025-35436

CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote attacker could cause a crash by providing a specially crafted email address or response. Fixed in commit 6a65a27.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisa:thorium:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-09-17 17:15

Updated : 2025-12-19 12:34


NVD link : CVE-2025-35436

Mitre link : CVE-2025-35436

CVE.ORG link : CVE-2025-35436


JSON object : View

Products Affected

cisa

  • thorium
CWE
CWE-248

Uncaught Exception