CVE-2025-27134: Joplin 3.3.3 Server - Privilege Escalation

HoneyLabs honeypots recorded 15 probes matching CVE-2025-27134 from 4 distinct source IP addresses in the last 7 days. Severity is rated high.

Request paths that identify it

  • /api/sessions

Addresses probing it

Source IPProbesNetworkCountry
147.139.204.1956Alibaba (US) Technology Co., Ltd.Indonesia
175.6.54.2506No.293,Wanbao AvenueChina
35.238.120.462Google LLCUnited States
34.170.15.11Google LLCUnited States

Networks it comes from

ASNOrganisationProbesSource IPs
AS63835No.293,Wanbao Avenue61
AS45102Alibaba (US) Technology Co., Ltd.61
AS396982Google LLC32

Captured requests

  • /api/sessions
  • /api/sessions?limit=1
  • /api/sessions/%7Bsession_id%7D
  • /api/sessions/

HTTP client fingerprints (JA4H)

  • ge11nn0500_2d30dc89d981
  • po11nn0700_1cd7ee9bf867
  • ge11nn0500_cac2c496544b

CVE report

CVE report

Open a specific CVE from the CVE tracker.