CVE-2025-29904

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Mar 12, 2025
CWE ID 444

Summary

CVE-2025-29904 is a newly disclosed vulnerability affecting JetBrains Ktor before version 3.1.1. This issue allows for HTTP Request Smuggling, enabling an attacker to conceal malicious HTTP requests within apparently innocuous ones, potentially leading to unintended server behavior or information disclosure. The impact of this vulnerability can range from denial of service to more serious security consequences, highlighting the importance of applying the necessary patch or upgrade to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share