Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-58369

Опубликовано: 05 сент. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

fs2 is a compositional, streaming I/O library for Scala. Versions up to and including 2.5.12, 3.0.0-M1 through 3.12.2, and 3.13.0-M1 through 3.13.0-M6 are vulnerable to denial of service attacks though TLS sessions using fs2-io on the JVM using the fs2.io.net.tls package. When establishing a TLS session, if one side of the connection shuts down write while the peer side is awaiting more data to progress the TLS handshake, the peer side will spin loop on the socket read, fully utilizing a CPU. The CPU is consumed until the overall connection is closed, potentially shutting down a fs2-io powered server. This issue is fixed in versions 2.5.13, 3.12.1, and 3.13.0-M7.

EPSS

Процентиль: 33%
0.00132
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.3
github
5 месяцев назад

FS2 half-shutdown of socket during TLS handshake may result in spin loop on opposite side

EPSS

Процентиль: 33%
0.00132
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400