First published: Mon Mar 03 2025(Updated: )
When NGINX Unit with the Java Language Module is in use, undisclosed requests can lead to an infinite loop and cause an increase in CPU resource utilization.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 NGINX Unit | >=1.29.1<=1.34.1 | 1.34.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-1695 is classified as high due to its potential to cause increased CPU resource utilization.
To fix CVE-2025-1695, upgrade NGINX Unit to version 1.34.2 or later.
CVE-2025-1695 affects NGINX Unit when using the Java Language Module, particularly versions between 1.29.1 and 1.34.1.
CVE-2025-1695 is a resource exhaustion vulnerability that can lead to an infinite loop.
F5 is responsible for addressing CVE-2025-1695 in their NGINX Unit software.