CVE-2025-25193
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2025-25193 is a denial-of-service vulnerability affecting Netty, a popular network application framework, up to and including version 4.1.118.Final. The issue arises due to an unsafe reading of environment files, which could lead to a crash if an attacker creates a large file that does not exist. This behavior is specific to Windows applications. Previously, a similar vulnerability, CVE-2024-47535, was addressed, but the fix was incomplete, failing to count null-bytes against the input limit. The latest fix can be found in commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Netty
Affected Vendors
- Netty