In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited files, an issue was identified: using an incorrect EOR configuration can cause inaccurate parsing and leave personally identifiable information (PII) unmasked.
Advisories

No advisories yet.

Fixes

Solution

For all affected versions, verify that masked files use the correct EOR configuration and that the EOR setting matches the file format.   * 1. Verify that EOR configuration matches the file format. * 2. Review masking job reports for expected row counts. * 3. Reconfigure jobs if discrepancies are found.


Workaround

No workaround given by the vendor.

History

Mon, 05 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Perforce delphix Continuous Compliance
CPEs cpe:2.3:a:perforce:delphix_continuous_compliance:*:*:*:*:*:*:*:*
Vendors & Products Perforce delphix Continuous Compliance
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 22 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 21 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft ms-dos
Microsoft windows
Perforce
Perforce perforce
Vendors & Products Microsoft
Microsoft ms-dos
Microsoft windows
Perforce
Perforce perforce

Sat, 20 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
Description In the versions of Delphix Continuous Compliance 2025.3.0 and above ,after a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited files, an issue was identified: using an incorrect EOR configuration can cause inaccurate parsing and leave personally identifiable information (PII) unmasked. In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited files, an issue was identified: using an incorrect EOR configuration can cause inaccurate parsing and leave personally identifiable information (PII) unmasked.

Sat, 20 Dec 2025 13:00:00 +0000

Type Values Removed Values Added
Description After a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited files, an issue was identified: using an incorrect EOR configuration can cause inaccurate parsing and leave personally identifiable information (PII) unmasked. In the versions of Delphix Continuous Compliance 2025.3.0 and above ,after a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited files, an issue was identified: using an incorrect EOR configuration can cause inaccurate parsing and leave personally identifiable information (PII) unmasked.

Sat, 20 Dec 2025 03:30:00 +0000

Type Values Removed Values Added
Description After a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited files, an issue was identified: using an incorrect EOR configuration can cause inaccurate parsing and leave personally identifiable information (PII) unmasked.
Title PII Leak Due to Change in EOR Handling
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Perforce

Published:

Updated: 2025-12-22T16:11:52.890Z

Reserved: 2025-12-12T16:01:02.586Z

Link: CVE-2025-14591

cve-icon Vulnrichment

Updated: 2025-12-22T16:11:47.818Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-20T04:16:08.017

Modified: 2026-01-05T17:58:21.763

Link: CVE-2025-14591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-21T21:12:31Z

Weaknesses