CVE-2025-22854: Possible thread exhaustion from processing http responses in PingFederate Google Adapter
Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal usage conditions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22854?
CVE-2025-22854 has been classified as a high severity vulnerability due to its potential to cause thread exhaustion.
How do I fix CVE-2025-22854?
To fix CVE-2025-22854, update to the latest version of the PingFederate Google Adapter that addresses the improper handling of non-200 HTTP responses.
What are the impacts of CVE-2025-22854?
CVE-2025-22854 can lead to service disruption and performance degradation through thread exhaustion under normal usage conditions.
Who is affected by CVE-2025-22854?
CVE-2025-22854 affects users of the PingFederate Google Adapter in any environment utilizing this integration.
What causes CVE-2025-22854?
CVE-2025-22854 is caused by improper handling of non-200 HTTP responses, which leads to an accumulation of threads.