Denial of Service Vulnerability in Confluence Data Center by Atlassian
CVE-2025-22166

8.3HIGH

Key Information:

Vendor

Atlassian

Vendor
CVE Published:
21 October 2025

What is CVE-2025-22166?

A Denial of Service (DoS) vulnerability affects Confluence Data Center, allowing attackers to render network resources unavailable to users. This vulnerability, affecting versions starting from 2.0, can be exploited to disrupt services temporarily or indefinitely, impacting users' access to vital functionality. Atlassian has released guidance urging users to upgrade their platforms to the specified versions that address this vulnerability, with details available in the release notes and download center.

Affected Version(s)

Confluence Data Center 9.5.1 to 9.5.4

Confluence Data Center 9.4.0 to 9.4.1

Confluence Data Center 9.3.1 to 9.3.2

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-22166 : Denial of Service Vulnerability in Confluence Data Center by Atlassian