ibmCVE-2025-12767
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.
Medium5.3CVE-2025-12767 · Published Sep 22, 2026 · updated Sep 23, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Concert Vendor | >= 1.0.0, <= 3.0.0 | No fix yet |
Details and references
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity from
- no source yet
- Weakness
- CWE-770