In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in CPU resource utilization. This vulnerability allows a remote attacker to cause a degradation that can lead to a limited denial-of-service (DoS).  There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
History

Wed, 05 Mar 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared F5
F5 nginx
CPEs cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
Vendors & Products F5
F5 nginx

Tue, 04 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Mar 2025 01:00:00 +0000

Type Values Removed Values Added
Description In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in CPU resource utilization. This vulnerability allows a remote attacker to cause a degradation that can lead to a limited denial-of-service (DoS).  There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Title NGINX Unit Java Vulnerability
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published: 2025-03-04T00:54:52.240Z

Updated: 2025-03-04T16:33:18.911Z

Reserved: 2025-02-25T16:18:53.086Z

Link: CVE-2025-1695

cve-icon Vulnrichment

Updated: 2025-03-04T16:33:15.179Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-04T01:15:10.063

Modified: 2025-03-05T15:18:38.660

Link: CVE-2025-1695

cve-icon Redhat

No data.