CVE-2025-25193

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Feb 10, 2025
Updated: Feb 21, 2025
CWE ID 400

Summary

CVE-2025-25193 is a denial-of-service vulnerability affecting Netty, a popular network application framework, up to and including version 4.1.118.Final. The issue arises due to an unsafe reading of environment files, which could lead to a crash if an attacker creates a large file that does not exist. This behavior is specific to Windows applications. Previously, a similar vulnerability, CVE-2024-47535, was addressed, but the fix was incomplete, failing to count null-bytes against the input limit. The latest fix can be found in commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share