{"id":"CVE-2025-14518","aliases":["GHSA-8xqm-6fj2-hfgf"],"url":"https://o3.security/vulnerability/CVE-2025-14518","summary":"PowerJob Network Request PingPongUtils.java checkConnectivity server-side request forgery","details":"A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powerjob/common/utils/net/PingPongUtils.java of the component Network Request Handler. The manipulation of the argument targetIp/targetPort leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.","published":"2025-12-11T15:02:08.153Z","modified":"2026-08-12T03:51:21.537778764Z","cvss":null,"epss":{"score":0.0035,"percentile":0.27665,"asOf":"2026-08-28"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"tech.powerjob:powerjob-common","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/PowerJob/PowerJob/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14518.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14518"},{"type":"ADVISORY","url":"https://vuldb.com/?id.335856"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.702896"},{"type":"REPORT","url":"https://github.com/PowerJob/PowerJob/issues/1144"},{"type":"REPORT","url":"https://github.com/PowerJob/PowerJob/issues/1144#issue-3673393002"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.335856"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:21.537778764Z"}}