Denial of Service Vulnerability in Octopus Server by Octopus Deploy
CVE-2025-0588
What is CVE-2025-0588?
In certain versions of Octopus Server, a vulnerability allows users with adequate permissions to manipulate custom headers in server responses. By crafting a specific referrer header, an attacker could cause all subsequent responses to result in server errors (500), leading to significant disruption and a denial of service condition. This manipulation can be repeatedly enabled or disabled to maintain service unavailability, creating a persistent denial of service state. Additionally, an attacker requires a valid CSRF token to execute this exploit while being unable to generate new tokens.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Octopus Server Windows 2020.1.0 < 2024.3.13097
Octopus Server Windows 2024.4.401 < 2024.4.7091
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
