CVE-2025-56132
A permanent, source-backed tracker page. Values are shown only when returned; explicit gaps and read failures remain different states.
What it is
ReportedLiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and invalid email addresses, allowing unauthenticated attackers to determine the existence of user accounts. Version 4.2 introduces user-based lockout mechanisms to mitigate brute-force attacks, user enumeration remains possible by default. In versions prior to 4.2, no such user-level protection is in place, only basic IP-based rate limiting is enforced.… Source description excerpt; complete tracked detail loads below.
NVD published: Sep 30, 2025 · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
What is affected
Reportedliquidfiles — liquidfiles. Product-level identification only; no affected-version conclusion is available from this field.
NVD published: Sep 30, 2025 · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
Urgency and basis
ReportedAct · 440.2
Tracker decision tier from the evidence detailed below · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
Exploitation evidence
Reportedkev-listed · VulnCheck KEV
VulnCheck KEV added: Apr 30, 2026 · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
What to do
ReportedApply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Tracked source remediation field · Source record updated: Aug 8, 2026 · Tracker snapshot: Aug 8, 2026
Evidence detail
Loading the full tracker evidence record…