PT-2025-9576 · Nginx · Nginx Unit

Tan Bui

·

Published

2025-03-03

·

Updated

2025-11-03

·

CVE-2025-1695

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions NGINX Unit versions prior to 1.34.2
Description The issue allows a remote attacker to cause a degradation that can lead to a limited denial-of-service (DoS) by sending undisclosed requests, which can lead to an infinite loop and increase CPU resource utilization. This is a data plane issue only, with no control plane exposure.
Recommendations For versions prior to 1.34.2, update to version 1.34.2 or later to resolve the issue.

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-10617
BIT-NGINX-2025-1695
CVE-2025-1695

Affected Products

Nginx Unit