CVE-2025-27421

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 3, 2025
CWE ID 400
CWE ID 772

Summary

CVE-2025-27421 is a vulnerability affecting the Abacus counting API. The issue lies in the server's Server-Sent Events (SSE) implementation, where a critical goroutine leak occurs when clients disconnect from the /stream endpoint. The server fails to properly clean up resources and terminate associated goroutines, leading to resource exhaustion. This vulnerability, caused by improper channel cleanup in the event handling mechanism, results in goroutines remaining blocked indefinitely and eventually causing the server to stop accepting new SSE connections while maintaining high memory usage. This vulnerability has been addressed in version 1.4.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Abacus GDS

Affected Vendors

  • Sabre Corporation