Infinite loop in starlette - CVE-2025-62727

 

Infinite loop in starlette - CVE-2025-62727

Published: October 29, 2025


Vulnerability identifier: #VU117790
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-62727
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop. A remote attacker can send a specially crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range parsing/merging logic and cause denial of service conditions.


Affected software

starlette
IBM Concert Software
IBM Cloud Pak for Security
IBM Process Mining
IBM Business Automation Workflow
Red Hat OpenShift AI (RHOAI)
watsonx.data integration
Maximo Application Suite - Visual Inspection Component
Maximo Application Suite Ai Service
Fedora
python-starlette
QRadar Suite

How to mitigate CVE-2025-62727

Install updates from vendor's website.

starlette - update to 0.49.1
IBM Concert Software - update to 2.2.0
IBM Cloud Pak for Security - update to 1.11.9.0
IBM Process Mining - update to 2.1.0
watsonx.data integration - update to 5.3.0
Maximo Application Suite - Visual Inspection Component - addressed in versions 8.9.20, 9.0.17, 9.1.10
Maximo Application Suite Ai Service - update to 9.1.10
IBM Business Automation Workflow - addressed in versions 24.0.0-IF008, 24.0.1-IF006, 25.0.0-IF003
python-starlette - addressed in versions 0.42.0-3.fc41, 0.47.0-2.el10_1, 0.47.0-2.el10_2, 0.47.3-2.fc42
QRadar Suite - update to 1.11.9.0
Red Hat OpenShift AI (RHOAI) - addressed in versions 2.22.3, 2.25.1

External References

Related Security Bulletins