CVE-2025-48039: Unverified Paths can Cause Excessive Use of System Resources
Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (sshsftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/sshsftpd.erl.
This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.
Other sources
Unverified Paths can Cause Excessive Use of System Resources
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48039?
CVE-2025-48039 is considered to have a moderate severity level due to the potential for resource leaks.
How do I fix CVE-2025-48039?
To fix CVE-2025-48039, upgrade Erlang OTP to a version higher than 28.0.3.
Which versions are affected by CVE-2025-48039?
CVE-2025-48039 affects Erlang OTP versions from 17.0 up to 28.0.3.
What components of Erlang are impacted by CVE-2025-48039?
CVE-2025-48039 impacts the ssh_sftp modules in Erlang OTP.
Is there any known workaround for CVE-2025-48039?
There are no known workarounds for CVE-2025-48039, so upgrading to a safe version is recommended.