7.1
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Description
Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.
This issue affects OTP form OTP 17.0 until OTP 28.0.3, OTP 27.3.4.3 and 26.2.5.15 corresponding to ssh from 3.0.1 until 5.3.3, 5.2.11.3 and 5.1.4.12.
This issue affects OTP form OTP 17.0 until OTP 28.0.3, OTP 27.3.4.3 and 26.2.5.15 corresponding to ssh from 3.0.1 until 5.3.3, 5.2.11.3 and 5.1.4.12.
Basic Information
ID
CVE-2025-48041
Source
EEF
Published
Sep 11, 2025 at 08:14
Affected Product
Vendor
Erlang
Product
OTP
Version
pkg:otp/[email protected]
Affected Versions
Erlang OTP pkg:otp/[email protected]
Erlang OTP 17.0
Erlang OTP 07b8f441ca711f9812fad9e9115bab3c3aa92f79
Erlang OTP 17.0
Erlang OTP 07b8f441ca711f9812fad9e9115bab3c3aa92f79