CVE-2026-25957
EUVD-2026-624609.02.2026, 23:16
Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. This vulnerability is fixed in 1.5.13 and 1.4.2.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cube | cube.js | 1.1.17 ≤ 𝑥 < 1.4.2 |
| cube | cube.js | 1.5.0 ≤ 𝑥 < 1.5.13 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration