← Vulnerability feed

Vulnerability record · CVE-2026-25957 · published 9 February 2026

CVE-2026-25957: Cube.js vulnerability

Cube · Cube.Js

Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. This vulnerability is fixed in 1.5.13 and 1.4.2.

6.5 CVSS 3.1 Medium EPSS 0.44% · top 64.5% CWE-755 · CWE-755
6.5CVSS 3.1 base score
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. This vulnerability is fixed in 1.5.13 and 1.4.2.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-25957 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-23510Cube.js sql injection vulnerabilitycube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run a…EPSS 0.94%7.7CVE-2026-25958Cube.js vulnerabilityCube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possible to make a specially crafted…EPSS 0.39%7.5CVE-2023-50709Cube.js improper input validation vulnerabilityCube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cube API unavailable by submitti…EPSS 0.72%7.8CVE-2024-29748Android Pixel logic error allows local privilege escalationCVE-2024-29748 is a logic error in Android code that permits bypassing a security check, leading to local escalation of privilege. It affects Google …KEVEPSS 0.67%analysed9.8CVE-2020-7247OpenSMTPD MAIL FROM command injection allows remote root code executionOpenSMTPD 6.6, as shipped in OpenBSD 6.6 and other products, mishandles input validation in smtp_mailaddr in smtp_session.c, returning an incorrect v…KEVEPSS 99%analysed8.6CVE-2018-0155Cisco Catalyst BFD offload incomplete header handling denial of serviceCisco Catalyst 4500 and 4500-X series switches mishandle incomplete BFD headers in the BFD offload implementation, causing the iosd process to crash.…KEVEPSS 7.7%analysed8.8CVE-2021-38003Google Chrome V8 heap corruption via crafted HTML pageGoogle Chrome before 95.0.4638.69 contains an inappropriate implementation in the V8 JavaScript engine that can lead to heap corruption. A remote att…KEVEPSS 39%analysed9.8CVE-2017-5638Apache Struts 2 Jakarta Multipart parser remote code executionThe Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type,…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2026-25957), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.