Denial-of-Service Vulnerability in NGINX Unit with Java Language Module
CVE-2025-1695

6.9MEDIUM

Key Information:

Vendor
F5
Vendor
CVE Published:
4 March 2025

Summary

A vulnerability in NGINX Unit before version 1.34.2, when using the Java Language Module, can be exploited by remote attackers through undisclosed requests. This leads to an infinite loop situation, significantly increasing CPU usage and potentially causing a denial of service by degrading the application's performance. The issue is confined to the data plane and does not expose any control plane vulnerabilities, meaning that the impacts are limited to service interruptions.

Affected Version(s)

NGINX Unit 1.11.0 < 1.34.2

NGINX Unit *

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tan Bui of Singapore Management University (SMU)
.