PT-2025-9576 · Nginx · Nginx Unit

Tan Bui

·

Publicado

2025-03-03

·

Atualizado

2025-11-03

·

CVE-2025-1695

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions NGINX Unit versions prior to 1.34.2
Description The issue allows a remote attacker to cause a degradation that can lead to a limited denial-of-service (DoS) by sending undisclosed requests, which can lead to an infinite loop and increase CPU resource utilization. This is a data plane issue only, with no control plane exposure.
Recommendations For versions prior to 1.34.2, update to version 1.34.2 or later to resolve the issue.

Correção

DoS

Infinite Loop

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-10617
BIT-NGINX-2025-1695
CVE-2025-1695

Produtos afetados

Nginx Unit