CVE-2025-52936: Improper Link Resolution Before File Access vulnerability in yrutschle/sslh
Published Jun 23, 2025
·Updated
Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: before 2.2.2.
Affected Software
2 affected componentsFixes available
YRutschle sslh<2.2.2
debian/sslh<=1.20-1, <=2.1.4-1
1.20-1+deb11u1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sslhto a version that resolves this vulnerability.Fixed in 1.20-1+deb11u1 - Upgrade
Upgrade
yrutschle/sslhto a version that resolves this vulnerability.Fixed in 2.2.2
Event History
Jun 23, 2025
CVE Published
via MITRE·09:25 AM
Data Sourced
via MITRE·09:25 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Jun 1, 2026
Data Sourced
via Ubuntu·06:32 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·06:32 PM
DescriptionAffected Software
Data Sourced
via Launchpad·06:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2025-52936?
CVE-2025-52936 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-52936?
To fix CVE-2025-52936, upgrade to sslh version 2.2.2 or later.
3
What causes CVE-2025-52936?
CVE-2025-52936 is caused by improper link resolution before file access in sslh.
4
Which versions of sslh are affected by CVE-2025-52936?
CVE-2025-52936 affects sslh versions prior to 2.2.2.
5
Is there a public exploit for CVE-2025-52936?
As of now, there are no known public exploits for CVE-2025-52936.