CVE-2025-55796
Published: 18 November 2025
Summary
CVE-2025-55796 is a high-severity Uncontrolled Resource Consumption (CWE-400) vulnerability in Openml Openml.Org. Its CVSS base score is 7.5 (High).
Operationally, ranked in the top 22.0% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
Deeper analysis
The openml/openml.org web application version v2.0.20241110 contains a vulnerability in its handling of critical user workflows including signup confirmation, password resets, email confirmation resends, and email change confirmation. Tokens for these operations are generated as MD5 hashes of the current timestamp in "%d %H:%M:%S" format, without incorporating user-specific data or cryptographic randomness, which produces highly predictable values.
Remote attackers with no authentication or user interaction required can observe or guess the narrow time window and brute-force valid tokens, allowing them to complete account confirmations, perform password resets, and approve email changes on arbitrary accounts, resulting in full account takeover.
An advisory describing the issue is available via the project's GitHub security advisory GHSA-xfjh-gf9p-8qr6. The associated EPSS score remains low with only a minor increase between its current value of 0.0105 and recorded peak of 0.0155.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-198034
Vulnerability details
The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflows such as signup confirmation, password resets, email confirmation resends, and email change confirmation. These tokens are generated by hashing the current timestamp formatted as "%d %H:%M:%S"…
more
without incorporating any user-specific data or cryptographic randomness. This predictability allows remote attackers to brute-force valid tokens within a small time window, enabling unauthorized account confirmation, password resets, and email change approvals, potentially leading to account takeover.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Limiting concurrent sessions directly prevents uncontrolled resource consumption by capping the number of active sessions per user or account.
Analysis identifies uncontrolled resource consumption indicative of denial-of-service or abuse attempts.
Contingency plan testing includes resource exhaustion scenarios to verify recovery, making it harder for attackers to sustain exploits that cause uncontrolled consumption.
Updated contingency plans include current procedures to detect, contain, and recover from resource exhaustion, limiting an attacker's ability to sustain impact from uncontrolled consumption.
Alternate site allows resumption of operations if resource exhaustion at the primary site is exploited to cause unavailability.
Alternate telecommunications services enable resumption of essential functions when primary services become unavailable due to uncontrolled resource consumption.
The team can analyze and respond to resource exhaustion incidents, reducing the impact of attacks that exploit uncontrolled consumption weaknesses.
Timely maintenance support and spare parts enable rapid recovery from failures induced by uncontrolled resource consumption, shortening the impact window of denial-of-service attacks.