Remote Code Execution Vulnerability in CISA Thorium by CISA
CVE-2025-35435

5.3MEDIUM

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
17 September 2025

What is CVE-2025-35435?

CISA Thorium has a vulnerability that allows a remote, authenticated attacker to exploit a flaw related to the handling of stream split sizes. When a stream split size of zero is accepted, it results in a division by this value, triggering a crash of the service. This issue can disrupt operations and lead to potential unauthorized access. The vulnerability has been addressed in the latest commit, ensuring that the service securely manages stream split sizes.

Affected Version(s)

Thorium 1.0.0 < 89101a6

Thorium 89101a6

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

, OpenAI Security Research
.
CVE-2025-35435 : Remote Code Execution Vulnerability in CISA Thorium by CISA