CVE-2025-35432: exploitation status and patch state
CVE-2025-35432 · CVSS 5.3 MEDIUM · EPSS 1%
CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker can send unlimited messages to a user who is pending verification. Fixed in 1.1.1 by adding a rate limit set by default to 10 minutes.
Is CVE-2025-35432 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 1%.
Public exploit code: none found in monitored sources.