CVE-2025-48040Uncontrolled Resource Consumption in OTP

Severity
6.9MEDIUMNVD
EPSS
0.2%
top 63.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 11
Latest updateOct 21

Description

Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP form OTP 17.0 until OTP 28.0.3, OTP 27.3.4.3 and 26.2.5.15 corresponding to ssh from 3.0.1 until 5.3.3, 5.2.11.3 and 5.1.4.12.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Packages1 packages

CVEListV5erlang/otp3.0.1*+2

🔴Vulnerability Details

2
CVEList
Malicious Key Exchange Messages may Lead to Excessive Resource Consumption2025-09-11
OSV
CVE-2025-48040: Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding2025-09-11

📋Vendor Advisories

4
Ubuntu
Erlang vulnerabilities2025-10-21
Red Hat
erlang: Erlang Excessive Resource Consumption2025-09-11
Microsoft
Malicious Key Exchange Messages may Lead to Excessive Resource Consumption2025-09-09
Debian
CVE-2025-48040: erlang - Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modu...2025
CVE-2025-48040 — Uncontrolled Resource Consumption | cvebase