CVE-2025-48038: Unverified File Handles can Cause Excessive Use of System Resources
Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (sshsftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/sshsftpd.erl.
This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.
Other sources
Unverified File Handles can Cause Excessive Use of System Resources
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48038?
CVE-2025-48038 is categorized as a medium severity vulnerability due to excessive resource allocation risks.
How do I fix CVE-2025-48038?
To mitigate CVE-2025-48038, upgrade Erlang OTP to version 28.0.4 or later where the vulnerability is resolved.
What impact does CVE-2025-48038 have on affected software?
CVE-2025-48038 can lead to resource leakage and potentially utilize excessive system resources causing denial of service.
Which versions of Erlang OTP are affected by CVE-2025-48038?
CVE-2025-48038 affects Erlang OTP versions from 17.0 up to 28.0.3.
What components are primarily impacted by CVE-2025-48038?
The vulnerability affects the ssh_sftp modules within the Erlang OTP ssh component.