Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.
This issue affects OTP form OTP 17.0 until OTP 28.0.3, OTP 27.3.4.3 and 26.2.5.15 corresponding to ssh from 3.0.1 until 5.3.3, 5.2.11.3 and 5.1.4.12.
Metrics
Affected Vendors & Products
References
History
Fri, 12 Sep 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Thu, 11 Sep 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 11 Sep 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP form OTP 17.0 until OTP 28.0.3, OTP 27.3.4.3 and 26.2.5.15 corresponding to ssh from 3.0.1 until 5.3.3, 5.2.11.3 and 5.1.4.12. | |
Title | SSH_FXP_OPENDIR may Lead to Exhaustion of File Handles | |
First Time appeared |
Erlang
Erlang erlang\/otp |
|
Weaknesses | CWE-400 CWE-770 |
|
CPEs | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* | |
Vendors & Products |
Erlang
Erlang erlang\/otp |
|
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: EEF
Published: 2025-09-11T08:14:20.508Z
Updated: 2025-09-12T03:19:05.890Z
Reserved: 2025-05-15T08:40:25.455Z
Link: CVE-2025-48041

Updated: 2025-09-11T13:30:22.815Z

Status : Awaiting Analysis
Published: 2025-09-11T09:15:34.603
Modified: 2025-09-11T17:14:10.147
Link: CVE-2025-48041
