CVE-2025-1695: NGINX Unit Java Vulnerability
In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in CPU resource utilization. This vulnerability allows a remote attacker to cause a degradation that can lead to a limited denial-of-service (DoS). There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Other sources
When NGINX Unit with the Java Language Module is in use, undisclosed requests can lead to an infinite loop and cause an increase in CPU resource utilization.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1695?
The severity of CVE-2025-1695 is classified as high due to its potential to cause increased CPU resource utilization.
How do I fix CVE-2025-1695?
To fix CVE-2025-1695, upgrade NGINX Unit to version 1.34.2 or later.
What does CVE-2025-1695 affect?
CVE-2025-1695 affects NGINX Unit when using the Java Language Module, particularly versions between 1.29.1 and 1.34.1.
What type of vulnerability is CVE-2025-1695?
CVE-2025-1695 is a resource exhaustion vulnerability that can lead to an infinite loop.
Who is responsible for addressing CVE-2025-1695?
F5 is responsible for addressing CVE-2025-1695 in their NGINX Unit software.