CVE-2025-48040: Malicious Key Exchange Messages may Lead to Excessive Resource Consumption
Malicious Key Exchange Messages may Lead to Excessive Resource Consumption
Other sources
Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (sshsftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/sshsftpd.erl.
This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48040?
CVE-2025-48040 is classified as an Uncontrolled Resource Consumption vulnerability.
How do I fix CVE-2025-48040?
To mitigate CVE-2025-48040, upgrade Erlang OTP to versions above 28.0.3.
What versions of Erlang OTP are affected by CVE-2025-48040?
CVE-2025-48040 affects Erlang OTP versions from 17.0 to 28.0.3.
Which Erlang SSH versions are impacted by CVE-2025-48040?
CVE-2025-48040 impacts Erlang SSH versions from 3.0.1 to 5.3.3.
What type of vulnerability is CVE-2025-48040?
CVE-2025-48040 is an Uncontrolled Resource Consumption vulnerability that allows for excessive allocation and flooding.