CVE-2025-35436: exploitation status and patch state
CVE-2025-35436 · CVSS 5.3 MEDIUM · EPSS 1%
CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote attacker could cause a crash by providing a specially crafted email address or response. Fixed in commit 6a65a27.
Is CVE-2025-35436 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 1%.
Public exploit code: none found in monitored sources.