CVE-2025-35435: CISA Thorium download stream divide by zero
Published Sep 17, 2025
·Updated
CISA Thorium accepts a stream split size of zero then divides by this value. A remote, authenticated attacker could cause the service to crash. Fixed in commit 89101a6.
Affected Software
2 affected components
CISA Thorium
CISA Thorium<=1.1.2
Event History
Sep 17, 2025
CVE Published
via MITRE·04:53 PM
Data Sourced
via MITRE·04:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-35435?
CVE-2025-35435 is considered a high severity vulnerability due to the potential for service crashes by authenticated attackers.
2
How do I fix CVE-2025-35435?
To mitigate CVE-2025-35435, update to the latest version of CISA Thorium as the vulnerability has been fixed in commit 89101a6.
3
Who is affected by CVE-2025-35435?
CVE-2025-35435 affects CISA Thorium software that accepts a stream split size of zero.
4
What type of attack is possible with CVE-2025-35435?
A remote, authenticated attacker can exploit CVE-2025-35435 to cause a crash in the CISA Thorium service.
5
When was CVE-2025-35435 discovered?
CVE-2025-35435 was disclosed in 2025, with a fix implemented in commit 89101a6.