Memory leak in undici - CVE-2025-47279

 

Memory leak in undici - CVE-2025-47279

Published: May 16, 2025


Vulnerability identifier: #VU109244
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-47279
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due memory leak when handling invalid certificates. A remote attacker can force the application to leak memory and perform denial of service attack.


Affected software

undici
Knowledge Catalog Premium Cartridge
Data Product Hub
Astronomer with IBM
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Automation Decision Services
App Connect Enterprise Certified Container
IBM Security QRadar Analyst Workflow

How to mitigate CVE-2025-47279

Install updates from vendor's website.

undici - addressed in versions 5.29.0, 6.21.2, 7.5.0
Knowledge Catalog Premium Cartridge - update to 5.2
Data Product Hub - update to 5.2.1
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
Astronomer with IBM - update to 1.1.0
IBM Security QRadar Analyst Workflow - update to 3.0.1
App Connect Enterprise Certified Container - addressed in versions 12.0.11, 12.10.0

External References

Related Security Bulletins