VYPR
High severity7.5OSV Advisory· Published Jul 5, 2025· Updated Apr 15, 2026

CVE-2025-53603

CVE-2025-53603

Description

In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request in which a parameter in the query string is a duplicate of a parameter in the POST body.

Affected products

1
  • Range: SOGo-2.0.1, SOGo-2.0.2, SOPE-3.0.1, …

Patches

1

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

7

News mentions

0

No linked articles in our index yet.