PT-2025-9576 · Nginx · Nginx Unit
Tan Bui
·
Publicado
2025-03-03
·
Atualizado
2025-11-03
·
CVE-2025-1695
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
NGINX Unit versions prior to 1.34.2
Description
The issue allows a remote attacker to cause a degradation that can lead to a limited denial-of-service (DoS) by sending undisclosed requests, which can lead to an infinite loop and increase CPU resource utilization. This is a data plane issue only, with no control plane exposure.
Recommendations
For versions prior to 1.34.2, update to version 1.34.2 or later to resolve the issue.
Correção
DoS
Infinite Loop
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nginx Unit