Skip to main content

CVE-2025-57403

7.5
HIGHCVSS v3.1 Base Score
0.11%
LOW RiskEPSS (29th percentile)

Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application concatenates the requested URL (or a portion of it) directly with a base path using os.path.join. This bypass allows directory traversal or absolute path injection, leading to the potential exposure of sensitive information.

Published: 12/26/2025
Modified: 1/9/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Score (Exploitation Probability)

0.11%LOW Exploitation Risk
29th percentile

This vulnerability has a 0.11% probability of being exploited in the next 30 days, ranking higher than 29% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-23)

Similar SeverityHIGH