CVE-2018-25031
MEDIUM 4.3EPSS 42.3%
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.
- CVSS v3.1
- 4.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N - CVSS v3.1
- 4.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N - CVSS v3.1
- 4.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N - EPSS
- 42.33% chance of exploitation in the next 30 days, 99th percentile
- Nuclei
- medium · CWE-20
- Published
- 2022-03-11
- Updated
- 2024-08-05
Proof-of-concept exploits (14)
- KonEch0/CVE-2018-25031-SG0★ · 2024-11-15
- LUCASRENAA/CVE-2018-250310★ · 2023-11-16
- RelicHunt3r/swagger-ui0★ · 2025-10-27
- afine-com/CVE-2018-250312★ · 2025-09-15
- geozin/POC-CVE-2018-250310★ · 2024-05-16
- h2oa/CVE-2018-250310★ · 2024-05-21
- h4ckt0m/CVE-2018-25031-test0★ · 2025-06-29
- hev0x/CVE-2018-25031-PoC0★ · 2024-01-03
- johnlaurance/CVE-2018-25031-test20★ · 2024-02-23
- mathis2001/CVE-2018-250313★ · 2026-05-11
- natpakun/SSRF-CVE-2018-25031-0★ · 2024-07-24
- nigartest/CVE-2018-250310★ · 2025-04-21
- rafaelcintralopes/SwaggerUI-CVE-2018-250312★ · 2023-04-14
- rasinfosec/CVE-2018-250310★ · 2026-01-26