First published: Mon Mar 03 2025(Updated: )
In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in CPU resource utilization. This vulnerability allows a remote attacker to cause a degradation that can lead to a limited denial-of-service (DoS). There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 NGINX Unit | >=1.29.1<=1.34.1 | 1.34.2 |
>=1.29.1<1.34.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-1695 is classified as high due to its potential to cause increased CPU resource utilization.
To fix CVE-2025-1695, upgrade NGINX Unit to version 1.34.2 or later.
CVE-2025-1695 affects NGINX Unit when using the Java Language Module, particularly versions between 1.29.1 and 1.34.1.
CVE-2025-1695 is a resource exhaustion vulnerability that can lead to an infinite loop.
F5 is responsible for addressing CVE-2025-1695 in their NGINX Unit software.