Denial-of-Service Vulnerability in NGINX Unit with Java Language Module
CVE-2025-1695
6.9MEDIUM
What is CVE-2025-1695?
A vulnerability in NGINX Unit before version 1.34.2, when using the Java Language Module, can be exploited by remote attackers through undisclosed requests. This leads to an infinite loop situation, significantly increasing CPU usage and potentially causing a denial of service by degrading the application's performance. The issue is confined to the data plane and does not expose any control plane vulnerabilities, meaning that the impacts are limited to service interruptions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
NGINX Unit 1.11.0 < 1.34.2
NGINX Unit *
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tan Bui of Singapore Management University (SMU)