CVE-2025-29908
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 407
Summary
CVE-2025-29908 is a recently disclosed vulnerability affecting the Netty QUIC codec, a QUIC codec for the Netty project that utilizes quiche. This issue involves a hash collision vulnerability found in the hash map used to manage connections. By initiating connections with colliding Source Connection IDs (SCIDs), remote attackers can trigger a considerable CPU load on the server, resulting in a Hash Denial of Service (DoS) attack. The vulnerability has been addressed in version 0.0.71.Final of the Netty project.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.