CISA Thorium Unauthenticated Remote Crash Vulnerability via Email Error Handling

Vulnerability

A vulnerability exists in CISA Thorium versions 1.0.0 prior to 6a65a27, where the application improperly manages errors related to account verification emails by using '.unwrap()'. This flaw allows an unauthenticated remote attacker to cause a crash by sending a specially crafted email address or response.

Impact

Exploitation of this vulnerability leads to a crash of the CISA Thorium application.

Remediation

This vulnerability has been fixed in CISA Thorium version 6a65a27.

Added: Sep 17, 2025, 5:19 PM
Updated: Sep 17, 2025, 5:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.5
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.