CVE-2025-48041
Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Floodin
CVSS
—
Sin CVSS
EPSS
0.4%
p32
KEV
—
Exploit Today
10
0-100
Publicado: 11 sept 2025 · Última mod.: 24 jul 2026 · CWE-400 · CWE-770
0.4%EPSS · 30 días0.4%
2026-08-232026-09-21
Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.
- cna.erlef.orghttps://cna.erlef.org/cves/CVE-2025-48041.html
- github.comhttps://github.com/erlang/otp/commit/5f9af63eec4657a37663828d206517828cb9f288
- github.comhttps://github.com/erlang/otp/commit/d49efa2d4fa9e6f7ee658719cd76ffe7a33c2401
- github.comhttps://github.com/erlang/otp/pull/10157
- github.comhttps://github.com/erlang/otp/security/advisories/GHSA-79c4-cvv7-4qm3
- osv.devhttps://osv.dev/vulnerability/EEF-CVE-2025-48041
- www.erlang.orghttps://www.erlang.org/doc/system/versions.html#order-of-versions
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-944497.5 ALT—
——0A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. The issue occurs when using the ApplyGuard or ApplyFaultTolerance annotations, where the library fails to release internal tracking objects after each request. This causes a steady increase in memory usage that eventually leads to the application slowing down and crashing due to lack of memory.4hCVE-2026-616297.5 ALT—
——0nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptLanguage` on the raw `Accept-Language` header without imposing any size or shape filter. The underlying parser has quadratic-time behaviour on long lists of malformed language tags. The CVE-2022-32149 guard that golang.org/x/text added in v0.3.8 caps the number of `-` characters in the input at 1000, but it does not cap `_` characters even though the parser's internal scanner aliases `_` to `-` before parsing. A single unauthenticated GET request with an `Accept-Language` header built out of `_` separators burns about 2.4 seconds of server CPU on the host running nginx-ignition; ten concurrent attackers saturate a ten-core box for the duration of the attack while consuming ~10 MiB/s of upstream bandwidth. Version 2.40.1 fixes this issue.7hCVE-2026-852203.7 BAJ—
——0A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot.
The vulnerability is accessible when the Redis service is enabled only.
The Canary is NOT affected if the Redis service is disabled.
Thinkst has addressed this issue on all supported platforms.
New update files to address this issue are available on all platforms except Docker. For Docker customers, a new Docker image has been published which includes the patch. Customers with automatic updates enabled already have updates in distribution. If automatic updates are disabled, customers are advised to update their Canaries.
Workarounds are available for customers unable to update at this time.7hCVE-2026-918674.3 MED—
——0When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service).
Users are recommended to upgrade to version 3.2.4, which fixes this issue.4hCVE-2026-918667.5 ALT—
——0A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service).
Users are recommended to upgrade to version 3.2.4, which fixes this issue.4hCVE-2026-918657.5 ALT—
——0A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service).
Users are recommended to upgrade to version 3.2.4, which fixes this issue.4h