CVE Feed

    Dashboard / CVE / CVE-2025-25193

    CVE-2025-25193

    Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crash. A similar issue was previously reported as CVE-2024-47535. This issue was fixed, but the fix was incomplete in that null-bytes were not counted against the input limit. Commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386 contains an updated fix.

    Published:Feb 10, 2025
    Last Modified:Jun 11, 2025
    EPS:Feb 10, 2025
    EPSS Score:0.00121
    CVSS Score:5.5

    Affected Products

    Vendor
    Microsoft
    Product
    Windows
    Vendor
    Netty
    Product
    Netty
    Vendor
    Redhat
    Product
    Amq Streams
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High