CVE-2025-6703: transport/fc.rs: panic attempting to send MAX_DATA with value larger max varint
Published Jun 26, 2025
·Updated
Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0.4.24 through 0.13.2.
Affected Software
2 affected components
Mozilla neqo>=0.4.24<=0.13.2
Mozilla Neqo Rust>=0.4.24<=0.13.2
Event History
Jun 26, 2025
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-6703?
CVE-2025-6703 is categorized as a low-severity vulnerability since it leads to an unexploitable crash.
2
How do I fix CVE-2025-6703?
To mitigate CVE-2025-6703, users should upgrade Mozilla neqo to a version beyond 0.13.2.
3
What versions of Mozilla neqo are affected by CVE-2025-6703?
CVE-2025-6703 affects Mozilla neqo versions from 0.4.24 up to and including 0.13.2.
4
Is CVE-2025-6703 a security risk?
While CVE-2025-6703 causes a crash, it is not considered a direct security risk as it is unexploitable.
5
What is the nature of the vulnerability in CVE-2025-6703?
CVE-2025-6703 is an improper input validation vulnerability that can result in crashes.