Kentico Xperience Denial-of-Service Vulnerability in GetResource Handler

Vulnerability

A denial-of-service vulnerability has been identified in Kentico Xperience versions through 12.0.98. This vulnerability allows remote attackers to disrupt service availability by sending specially crafted requests to the GetResource handler. The issue arises from improper input validation, which enables these maliciously constructed requests to cause service disruptions.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing a disruption in service availability.

Remediation

Users can apply the latest hotfix available for their Kentico Xperience version. Instructions for applying hotfixes can be found on the Kentico Xperience DevNet hotfixes page.

Added: Dec 18, 2025, 8:31 PM
Updated: Dec 18, 2025, 8:31 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
7.6
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.