Loading
Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. This vulnerability is fixed in 1.5.13 and 1.4.2.
Use CWE-755, Cube vendor hub and Cube.Js product page to widen CVE-2026-25957 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-23510, CVE-2026-25958 and CVE-2023-50709 for nearby disclosures in the same product family.