CVE-2025-29904
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Mar 12, 2025
CWE ID 444
Summary
CVE-2025-29904 is a newly disclosed vulnerability affecting JetBrains Ktor before version 3.1.1. This issue allows for HTTP Request Smuggling, enabling an attacker to conceal malicious HTTP requests within apparently innocuous ones, potentially leading to unintended server behavior or information disclosure. The impact of this vulnerability can range from denial of service to more serious security consequences, highlighting the importance of applying the necessary patch or upgrade to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Jetbrains Ktor
Affected Vendors
- JetBrains